CVE-2008-4456
Summary
| CVE | CVE-2008-4456 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-06 23:25:50 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mysql | Mysql | 5.0.30 | All | All | All |
| Application | Mysql | Mysql | 5.0.36 | All | All | All |
| Application | Mysql | Mysql | 5.0.4 | All | All | All |
| Application | Mysql | Mysql | 5.0.44 | All | All | All |
| Application | Oracle | Mysql | 5.0.26 | All | All | All |
| Application | Oracle | Mysql | 5.0.27 | All | All | All |
| Application | Oracle | Mysql | 5.0.30 | sp1 | All | All |
| Application | Oracle | Mysql | 5.0.32 | All | All | All |
| Application | Oracle | Mysql | 5.0.33 | All | All | All |
| Application | Oracle | Mysql | 5.0.37 | All | All | All |
| Application | Oracle | Mysql | 5.0.38 | All | All | All |
| Application | Oracle | Mysql | 5.0.41 | All | All | All |
| Application | Oracle | Mysql | 5.0.42 | All | All | All |
| Application | Oracle | Mysql | 5.0.45 | All | All | All |
| Application | Oracle | Mysql | 5.0.67 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-897-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| MySQL command-line client HTML injection vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.henlich.de | |
| MySQL HTML Output Script Insertion Security Issue - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| MySQL Bugs: #27884: mysql --html does not quote HTML special characters in output | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | Exploit |
| Debian -- Security Information -- DSA-1783-1 mysql-dfsg-5.0 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Red Hat update for mysql - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Debian update for mysql-dfsg - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| MySQL command-line client HTML injection vulnerability - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Support / Security / Advisories / / MDVSA-2009:094 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| About the security content of Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Ubuntu update for mysql-dfsg-5 and mysql-dfsg-5.1 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-1397-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| MySQL Command Line Client HTML Special Characters HTML Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Bugtraq: RE: RE: MySQL command-line client HTML injection vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-02-17 | Tomas Hoger | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-4456 This issue was addressed for Red Hat Enterprise Linux 5 by https://rhn.redhat.com/errata/RHSA-2009-1289.html and Red Hat Enterprise Linux 4 by https://rhn.redhat.com/errata/RHSA-2010-0110.html . The Red Hat Security Response Team has rated this issue as having low security impact, future MySQL package updates may address this flaw for Red Hat Enterprise Linux 3, and Red Hat Application Stack 2. |
There are currently no legacy QID mappings associated with this CVE.