ID:4331 - Exploit for SQL injection in mysql - CVE-2009-5026

 
Main Vulnerability Database Exploits ID:4331 - Exploit for SQL injection in mysql - CVE-2009-5026

ID:4331 - Exploit for SQL injection in mysql - CVE-2009-5026

Published: August 11, 2020


Vulnerability identifier: #VU43713
Vulnerability risk: Medium
CVE-ID: CVE-2009-5026
CWE-ID: CWE-89
Exploitation vector: Remote access
Vulnerable software:
mysql

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.


Remediation

Install update from vendor's website.