LWN.net Logo

mysql: cross-site scripting

Package(s):mysql CVE #(s):CVE-2008-4456
Created:April 29, 2009 Updated:March 8, 2010
Description: From the Debian advisory: Thomas Henlich reported that the MySQL commandline client application did not encode HTML special characters when run in HTML output mode (that is, "mysql --html ..."). This could potentially lead to cross-site scripting or unintended script privilege escalation if the resulting output is viewed in a browser or incorporated into a web site.
Alerts:
rPath rPSA-2010-0014-1 2010-03-07
Ubuntu USN-897-1 2010-02-10
Mandriva MDVSA-2009:326 2009-12-07
CentOS CESA-2010:0110 2010-02-17
Red Hat RHSA-2010:0110-01 2010-02-16
Red Hat RHSA-2009:1461-01 2009-09-23
CentOS CESA-2009:1289 2009-09-15
Red Hat RHSA-2009:1289-02 2009-09-02
SuSE SUSE-SR:2009:014 2009-09-01
Debian DSA-1783 2009-04-29
Gentoo 201201-02 2012-01-05
Ubuntu USN-1397-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds