← Back

CVE-2009-5026

nvd nist
Published: Aug 17, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.

Affected (85)

Products: Mysql: Mysql · Oracle: Mysql
1 product
Mysql
1 product
Mysql
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Mysql
Version 5.0.0
Version 5.0.10
Version 5.0.15
Version 5.0.16
Version 5.0.17
Version 5.0.1
Version 5.0.20
Version 5.0.24
Version 5.0.2
Version 5.0.3
Version 5.0.45 b
Version 5.0.4
Version 5.0.5
Version 5.0.82
Version 5.0.84
Version 5.0.87
Oracle
Version 5.0.23
Version 5.0.41
Version 5.0.45
Version 5.0.51
Version 5.0.67
Version 5.0.75
Version 5.0.77
Version 5.0.81
Version 5.0.83
Version 5.0.85
Version 5.0.86
Version 5.0.88
Version 5.0.89
Version 5.0.90
Version 5.0.91
Version 5.0.92
Configuration B
53 vulnerable
Vulnerable SoftwareAffected Versions
Mysql
Version 5.1.23
Version 5.1.31
Version 5.1.32
Version 5.1.34
Version 5.1.37
Oracle
Version 5.1.10
Version 5.1.11
Version 5.1.12
Version 5.1.13
Version 5.1.14
Version 5.1.15
Version 5.1.16
Version 5.1.17
Version 5.1.18
Version 5.1.19
Version 5.1.1
Version 5.1.20
Version 5.1.21
Version 5.1.22
Version 5.1.23 a
Version 5.1.24
Version 5.1.25
Version 5.1.26
Version 5.1.27
Version 5.1.28
Version 5.1.29
Version 5.1.2
Version 5.1.30
Version 5.1.31 sp1
Version 5.1.33
Version 5.1.34 sp1
Version 5.1.35
Version 5.1.36
Version 5.1.37 sp1
Version 5.1.38
Version 5.1.39
Version 5.1.3
Version 5.1.40
Version 5.1.40 sp1
Version 5.1.41
Version 5.1.42
Version 5.1.43
Version 5.1.43 sp1
Version 5.1.44
Version 5.1.45
Version 5.1.46
Version 5.1.46 sp1
Version 5.1.47
Version 5.1.48
Version 5.1.49
Version 5.1.49 sp1
Version 5.1.4
Version 5.1

References (14)

Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.