PoC Index

CVE-2006-0903

MEDIUM 4.6EPSS 1.4%

MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.

CVSS v2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.37% chance of exploitation in the next 30 days, 70th percentile
Published
2006-02-27
Updated
2024-08-07

ExploitDB entries (1)

References

Related