PT-2009-1194 · Apache+1 · Mod-Auth-Mysql+2

Martin Joey Schulze

·

Published

2009-01-22

·

Updated

2018-10-30

·

CVE-2008-2384

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server 2.x with mod-auth-mysql module
Description A SQL injection issue exists in the mod-auth-mysql module for the Apache HTTP Server, specifically in the mod auth mysql.c file. This occurs when the module is configured to use a multibyte character set that permits a backslash as part of the character encoding. As a result, remote attackers can execute arbitrary SQL commands by providing specially crafted inputs in a login request.
Recommendations For Apache HTTP Server 2.x with the mod-auth-mysql module, consider disabling the use of multibyte character sets that allow backslashes until a patch is available. Restrict access to the mod-auth-mysql module to minimize the risk of exploitation. Avoid using the backslash character in login requests to the affected module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2384
RHSA-2009:0259
RHSA-2009_0259
RHSA-2010:1002
RHSA-2010_1002

Affected Products

Apache Http Server
Red Hat
Mod-Auth-Mysql