PoC Index

CVE-2008-6992

HIGH 7.5EPSS 1.4%

GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.38% chance of exploitation in the next 30 days, 70th percentile
Published
2009-08-18
Updated
2024-09-16

ExploitDB entries (1)

References

Related