CVE-2008-4456
06.10.2008, 23:25
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
Vendor | Product | Version |
---|---|---|
mysql | mysql | 5.0.4 |
mysql | mysql | 5.0.30 |
mysql | mysql | 5.0.36 |
mysql | mysql | 5.0.44 |
oracle | mysql | 5.0.26 |
oracle | mysql | 5.0.27 |
oracle | mysql | 5.0.30:sp1 |
oracle | mysql | 5.0.32 |
oracle | mysql | 5.0.33 |
oracle | mysql | 5.0.37 |
oracle | mysql | 5.0.38 |
oracle | mysql | 5.0.41 |
oracle | mysql | 5.0.42 |
oracle | mysql | 5.0.45 |
oracle | mysql | 5.0.67 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mysql-5.1 |
| ||||||||||||||||||||
mysql-dfsg-5.0 |
| ||||||||||||||||||||
mysql-dfsg-5.1 |
|
References