CVE-2009-5026

EUVD-2009-4984
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
mysqlmysql
5.0.0
mysqlmysql
5.0.1
mysqlmysql
5.0.2
mysqlmysql
5.0.3
mysqlmysql
5.0.4
mysqlmysql
5.0.5
mysqlmysql
5.0.10
mysqlmysql
5.0.15
mysqlmysql
5.0.16
mysqlmysql
5.0.17
mysqlmysql
5.0.20
mysqlmysql
5.0.24
mysqlmysql
5.0.45:b
mysqlmysql
5.0.82
mysqlmysql
5.0.84
mysqlmysql
5.0.87
oraclemysql
5.0.23
oraclemysql
5.0.41
oraclemysql
5.0.45
oraclemysql
5.0.51
oraclemysql
5.0.67
oraclemysql
5.0.75
oraclemysql
5.0.77
oraclemysql
5.0.81
oraclemysql
5.0.83
oraclemysql
5.0.85
oraclemysql
5.0.86
oraclemysql
5.0.88
oraclemysql
5.0.89
oraclemysql
5.0.90
oraclemysql
5.0.91
oraclemysql
5.0.92
mysqlmysql
5.1.23
mysqlmysql
5.1.31
mysqlmysql
5.1.32
mysqlmysql
5.1.34
mysqlmysql
5.1.37
oraclemysql
5.1
oraclemysql
5.1.1
oraclemysql
5.1.2
oraclemysql
5.1.3
oraclemysql
5.1.4
oraclemysql
5.1.10
oraclemysql
5.1.11
oraclemysql
5.1.12
oraclemysql
5.1.13
oraclemysql
5.1.14
oraclemysql
5.1.15
oraclemysql
5.1.16
oraclemysql
5.1.17
oraclemysql
5.1.18
oraclemysql
5.1.19
oraclemysql
5.1.20
oraclemysql
5.1.21
oraclemysql
5.1.22
oraclemysql
5.1.23:a
oraclemysql
5.1.24
oraclemysql
5.1.25
oraclemysql
5.1.26
oraclemysql
5.1.27
oraclemysql
5.1.28
oraclemysql
5.1.29
oraclemysql
5.1.30
oraclemysql
5.1.31:sp1
oraclemysql
5.1.33
oraclemysql
5.1.34:sp1
oraclemysql
5.1.35
oraclemysql
5.1.36
oraclemysql
5.1.37:sp1
oraclemysql
5.1.38
oraclemysql
5.1.39
oraclemysql
5.1.40
oraclemysql
5.1.40:sp1
oraclemysql
5.1.41
oraclemysql
5.1.42
oraclemysql
5.1.43
oraclemysql
5.1.43:sp1
oraclemysql
5.1.44
oraclemysql
5.1.45
oraclemysql
5.1.46
oraclemysql
5.1.46:sp1
oraclemysql
5.1.47
oraclemysql
5.1.48
oraclemysql
5.1.49
oraclemysql
5.1.49:sp1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mysql-5.1
hardy
dne
lucid
dne
maverick
Fixed 5.1.61-0ubuntu0.10.10.1
released
natty
not-affected
oneiric
not-affected
mysql-cluster-7.0
hardy
dne
lucid
ignored
maverick
ignored
natty
ignored
oneiric
ignored
mysql-dfsg-5.0
hardy
not-affected
lucid
dne
maverick
dne
natty
dne
oneiric
dne
mysql-dfsg-5.1
hardy
dne
lucid
Fixed 5.1.61-0ubuntu0.10.04.1
released
maverick
dne
natty
dne
oneiric
dne