CVE-2008-4456

EUVD-2008-4437
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document.  NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
Affected Products (NVD)
VendorProductVersion
mysqlmysql
5.0.4
mysqlmysql
5.0.30
mysqlmysql
5.0.36
mysqlmysql
5.0.44
oraclemysql
5.0.26
oraclemysql
5.0.27
oraclemysql
5.0.30:sp1
oraclemysql
5.0.32
oraclemysql
5.0.33
oraclemysql
5.0.37
oraclemysql
5.0.38
oraclemysql
5.0.41
oraclemysql
5.0.42
oraclemysql
5.0.45
oraclemysql
5.0.67
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mysql-5.1
dapper
dne
hardy
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
not-affected
natty
not-affected
mysql-dfsg-5.0
dapper
Fixed 5.0.22-0ubuntu6.06.12
released
feisty
ignored
gutsy
ignored
hardy
Fixed 5.0.51a-3ubuntu5.5
released
intrepid
Fixed 5.0.67-0ubuntu6.1
released
jaunty
Fixed 5.1.30really5.0.75-0ubuntu10.3
released
karmic
ignored
lucid
dne
maverick
dne
natty
dne
mysql-dfsg-5.1
dapper
dne
hardy
dne
intrepid
dne
jaunty
ignored
karmic
not-affected
lucid
not-affected
maverick
dne
natty
dne
References