mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
References
Link | Resource |
---|---|
https://gist.github.com/viraptor/881276ea61e8d56bac6e28454c79f1e6 | Exploit Third Party Advisory |
https://github.com/nedap/mysql-binuuid-rails/pull/18 | Patch Third Party Advisory |
https://gist.github.com/viraptor/881276ea61e8d56bac6e28454c79f1e6 | Exploit Third Party Advisory |
https://github.com/nedap/mysql-binuuid-rails/pull/18 | Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 03:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/viraptor/881276ea61e8d56bac6e28454c79f1e6 - Exploit, Third Party Advisory | |
References | () https://github.com/nedap/mysql-binuuid-rails/pull/18 - Patch, Third Party Advisory |
Information
Published : 2018-10-24 21:29
Updated : 2024-11-21 03:56
NVD link : CVE-2018-18476
Mitre link : CVE-2018-18476
CVE.ORG link : CVE-2018-18476
JSON object : View
Products Affected
nedap
- mysql-binuuid-rails
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')