CVE-2008-4456

Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document.  NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
mysqlmysql
5.0.4
mysqlmysql
5.0.30
mysqlmysql
5.0.36
mysqlmysql
5.0.44
oraclemysql
5.0.26
oraclemysql
5.0.27
oraclemysql
5.0.30:sp1
oraclemysql
5.0.32
oraclemysql
5.0.33
oraclemysql
5.0.37
oraclemysql
5.0.38
oraclemysql
5.0.41
oraclemysql
5.0.42
oraclemysql
5.0.45
oraclemysql
5.0.67
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mysql-5.1
natty
not-affected
maverick
not-affected
lucid
dne
karmic
dne
jaunty
dne
hardy
dne
dapper
dne
mysql-dfsg-5.0
natty
dne
maverick
dne
lucid
dne
karmic
ignored
jaunty
Fixed 5.1.30really5.0.75-0ubuntu10.3
released
intrepid
Fixed 5.0.67-0ubuntu6.1
released
hardy
Fixed 5.0.51a-3ubuntu5.5
released
gutsy
ignored
feisty
ignored
dapper
Fixed 5.0.22-0ubuntu6.06.12
released
mysql-dfsg-5.1
natty
dne
maverick
dne
lucid
not-affected
karmic
not-affected
jaunty
ignored
intrepid
dne
hardy
dne
dapper
dne
References