CVE-2009-5026

The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
mysqlmysql
5.0.0
mysqlmysql
5.0.1
mysqlmysql
5.0.2
mysqlmysql
5.0.3
mysqlmysql
5.0.4
mysqlmysql
5.0.5
mysqlmysql
5.0.10
mysqlmysql
5.0.15
mysqlmysql
5.0.16
mysqlmysql
5.0.17
mysqlmysql
5.0.20
mysqlmysql
5.0.24
mysqlmysql
5.0.45:b
mysqlmysql
5.0.82
mysqlmysql
5.0.84
mysqlmysql
5.0.87
oraclemysql
5.0.23
oraclemysql
5.0.41
oraclemysql
5.0.45
oraclemysql
5.0.51
oraclemysql
5.0.67
oraclemysql
5.0.75
oraclemysql
5.0.77
oraclemysql
5.0.81
oraclemysql
5.0.83
oraclemysql
5.0.85
oraclemysql
5.0.86
oraclemysql
5.0.88
oraclemysql
5.0.89
oraclemysql
5.0.90
oraclemysql
5.0.91
oraclemysql
5.0.92
mysqlmysql
5.1.23
mysqlmysql
5.1.31
mysqlmysql
5.1.32
mysqlmysql
5.1.34
mysqlmysql
5.1.37
oraclemysql
5.1
oraclemysql
5.1.1
oraclemysql
5.1.2
oraclemysql
5.1.3
oraclemysql
5.1.4
oraclemysql
5.1.10
oraclemysql
5.1.11
oraclemysql
5.1.12
oraclemysql
5.1.13
oraclemysql
5.1.14
oraclemysql
5.1.15
oraclemysql
5.1.16
oraclemysql
5.1.17
oraclemysql
5.1.18
oraclemysql
5.1.19
oraclemysql
5.1.20
oraclemysql
5.1.21
oraclemysql
5.1.22
oraclemysql
5.1.23:a
oraclemysql
5.1.24
oraclemysql
5.1.25
oraclemysql
5.1.26
oraclemysql
5.1.27
oraclemysql
5.1.28
oraclemysql
5.1.29
oraclemysql
5.1.30
oraclemysql
5.1.31:sp1
oraclemysql
5.1.33
oraclemysql
5.1.34:sp1
oraclemysql
5.1.35
oraclemysql
5.1.36
oraclemysql
5.1.37:sp1
oraclemysql
5.1.38
oraclemysql
5.1.39
oraclemysql
5.1.40
oraclemysql
5.1.40:sp1
oraclemysql
5.1.41
oraclemysql
5.1.42
oraclemysql
5.1.43
oraclemysql
5.1.43:sp1
oraclemysql
5.1.44
oraclemysql
5.1.45
oraclemysql
5.1.46
oraclemysql
5.1.46:sp1
oraclemysql
5.1.47
oraclemysql
5.1.48
oraclemysql
5.1.49
oraclemysql
5.1.49:sp1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mysql-5.1
oneiric
not-affected
natty
not-affected
maverick
Fixed 5.1.61-0ubuntu0.10.10.1
released
lucid
dne
hardy
dne
mysql-cluster-7.0
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
dne
mysql-dfsg-5.0
oneiric
dne
natty
dne
maverick
dne
lucid
dne
hardy
not-affected
mysql-dfsg-5.1
oneiric
dne
natty
dne
maverick
dne
lucid
Fixed 5.1.61-0ubuntu0.10.04.1
released
hardy
dne