Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2006-2753

SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.

  • Published: Jun 1, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-2753
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
mysql / mysql 5.0.5 5.0.5.x
mysql / mysql 5.0.10 5.0.10.x
mysql / mysql 5.0.0 5.0.0.x
mysql / mysql 5.0.15 5.0.15.x
mysql / mysql 5.0.17 5.0.17.x
mysql / mysql 4.1.13 4.1.13.x
mysql / mysql 5.0.3 5.0.3.x
mysql / mysql 4.1.15 4.1.15.x
mysql / mysql 4.1.8 4.1.8.x
mysql / mysql 4.1.14 4.1.14.x
mysql / mysql 4.1.12 4.1.12.x
mysql / mysql 4.1.10 4.1.10.x
mysql / mysql 5.0.2 5.0.2.x
mysql / mysql 5.0.20 5.0.20.x
mysql / mysql 5.0.1 5.0.1.x
mysql / mysql 4.1.0 4.1.0.x
mysql / mysql 5.0.4 5.0.4.x
mysql / mysql 4.1.3 4.1.3.x
mysql / mysql 5.0.16 5.0.16.x
mysql / mysql 4.1.2 4.1.2.x
oracle / mysql 4.1.1 4.1.1.x
oracle / mysql 4.1.4 4.1.4.x
oracle / mysql 4.1.5 4.1.5.x
oracle / mysql 4.1.6 4.1.6.x
oracle / mysql 4.1.7 4.1.7.x
oracle / mysql 4.1.9 4.1.9.x
oracle / mysql 4.1.11 4.1.11.x
oracle / mysql 4.1.16 4.1.16.x
oracle / mysql 4.1.17 4.1.17.x
oracle / mysql 4.1.18 4.1.18.x
oracle / mysql 4.1.19 4.1.19.x
oracle / mysql 5.0.6 5.0.6.x
oracle / mysql 5.0.11 5.0.11.x
oracle / mysql 5.0.12 5.0.12.x
oracle / mysql 5.0.13 5.0.13.x
oracle / mysql 5.0.14 5.0.14.x
oracle / mysql 5.0.18 5.0.18.x
oracle / mysql 5.0.19 5.0.19.x
oracle / mysql 5.0.21 5.0.21.x
oracle / mysql 5.0.7 5.0.7.x
oracle / mysql 5.0.8 5.0.8.x
oracle / mysql 5.0.9 5.0.9.x