|
|
| |
|
| |
mysql: cross-site scripting
| Package(s): | mysql |
CVE #(s): | CVE-2008-4456
|
| Created: | April 29, 2009 |
Updated: | March 8, 2010 |
| Description: |
From the Debian advisory: Thomas Henlich reported that the MySQL commandline client application
did not encode HTML special characters when run in HTML output mode
(that is, "mysql --html ..."). This could potentially lead to
cross-site scripting or unintended script privilege escalation if
the resulting output is viewed in a browser or incorporated into
a web site. |
| Alerts: |
|
( Log in to post comments)
|
|
|