Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.64532
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
Resumen:The remote host is missing an update to apache-mod_auth_mysql;announced via advisory MDVSA-2009:189.
Descripción:Summary:
The remote host is missing an update to apache-mod_auth_mysql
announced via advisory MDVSA-2009:189.

Vulnerability Insight:
A vulnerability has been found and corrected in mod_auth_mysql:

SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql
(aka libapache2-mod-auth-mysql) module for the Apache HTTP Server
2.x allows remote attackers to execute arbitrary SQL commands via
multibyte character encodings for unspecified input (CVE-2008-2384).

This update provides fixes for this vulnerability.

Affected: 2008.1, 2009.0, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2008-2384
BugTraq ID: 33392
http://www.securityfocus.com/bid/33392
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053899.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053903.html
http://openwall.com/lists/oss-security/2009/01/21/10
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10172
http://www.redhat.com/support/errata/RHSA-2009-0259.html
http://www.redhat.com/support/errata/RHSA-2010-1002.html
http://secunia.com/advisories/33627
http://secunia.com/advisories/43302
http://www.vupen.com/english/advisories/2009/0226
http://www.vupen.com/english/advisories/2011/0367
XForce ISS Database: modauthmysql-multibyte-sql-injection(48163)
https://exchange.xforce.ibmcloud.com/vulnerabilities/48163
CopyrightCopyright (C) 2009 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.