CVE-2015-9244
29.05.2018, 20:29
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Vendor | Product | Version |
---|---|---|
mysqljs | mysql | 𝑥 ≤ 0.9.6 |
mysqljs | mysql | 2.0.0:alpha |
mysqljs | mysql | 2.0.0:alpha2 |
mysqljs | mysql | 2.0.0:alpha3 |
mysqljs | mysql | 2.0.0:alpha4 |
mysqljs | mysql | 2.0.0:alpha7 |
mysqljs | mysql | 2.0.0:preview |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases