Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-0903


MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.


Published

2006-02-27T23:02:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mysql mysql 4.1.0 Yes
Application mysql mysql 4.1.3 Yes
Application mysql mysql 4.1.8 Yes
Application mysql mysql 4.1.10 Yes
Application mysql mysql 4.1.12 Yes
Application mysql mysql 4.1.13 Yes
Application mysql mysql 4.1.14 Yes
Application mysql mysql 4.1.15 Yes
Application mysql mysql 5.0.1 Yes
Application mysql mysql 5.0.2 Yes
Application mysql mysql 5.0.4 Yes
Application mysql mysql 5.0.5 Yes
Application mysql mysql 5.0.10 Yes
Application mysql mysql 5.0.15 Yes
Application mysql mysql 5.0.16 Yes
Application mysql mysql 5.0.17 Yes
Application oracle mysql 3.23 Yes
Application oracle mysql 3.23.0 Yes
Application oracle mysql 3.23.1 Yes
Application oracle mysql 3.23.2 Yes
Application oracle mysql 3.23.3 Yes
Application oracle mysql 3.23.4 Yes
Application oracle mysql 3.23.5 Yes
Application oracle mysql 3.23.6 Yes
Application oracle mysql 3.23.7 Yes
Application oracle mysql 3.23.8 Yes
Application oracle mysql 3.23.9 Yes
Application oracle mysql 3.23.10 Yes
Application oracle mysql 3.23.11 Yes
Application oracle mysql 3.23.12 Yes
Application oracle mysql 3.23.13 Yes
Application oracle mysql 3.23.14 Yes
Application oracle mysql 3.23.15 Yes
Application oracle mysql 3.23.16 Yes
Application oracle mysql 3.23.17 Yes
Application oracle mysql 3.23.18 Yes
Application oracle mysql 3.23.19 Yes
Application oracle mysql 3.23.20 Yes
Application oracle mysql 3.23.21 Yes
Application oracle mysql 3.23.22 Yes
Application oracle mysql 3.23.23 Yes
Application oracle mysql 3.23.24 Yes
Application oracle mysql 3.23.25 Yes
Application oracle mysql 3.23.26 Yes
Application oracle mysql 3.23.27 Yes
Application oracle mysql 3.23.28 Yes
Application oracle mysql 3.23.29 Yes
Application oracle mysql 3.23.30 Yes
Application oracle mysql 3.23.31 Yes
Application oracle mysql 3.23.32 Yes
Application oracle mysql 3.23.33 Yes
Application oracle mysql 3.23.34 Yes
Application oracle mysql 3.23.35 Yes
Application oracle mysql 3.23.36 Yes
Application oracle mysql 3.23.37 Yes
Application oracle mysql 3.23.38 Yes
Application oracle mysql 3.23.39 Yes
Application oracle mysql 3.23.40 Yes
Application oracle mysql 3.23.41 Yes
Application oracle mysql 3.23.42 Yes
Application oracle mysql 3.23.43 Yes
Application oracle mysql 3.23.44 Yes
Application oracle mysql 3.23.45 Yes
Application oracle mysql 3.23.46 Yes
Application oracle mysql 3.23.47 Yes
Application oracle mysql 3.23.48 Yes
Application oracle mysql 3.23.49 Yes
Application oracle mysql 3.23.50 Yes
Application oracle mysql 3.23.51 Yes
Application oracle mysql 3.23.52 Yes
Application oracle mysql 3.23.53 Yes
Application oracle mysql 3.23.54 Yes
Application oracle mysql 3.23.55 Yes
Application oracle mysql 3.23.56 Yes
Application oracle mysql 3.23.57 Yes
Application oracle mysql 3.23.58 Yes
Application oracle mysql 3.23.59 Yes
Application oracle mysql 4.0.0 Yes
Application oracle mysql 4.0.1 Yes
Application oracle mysql 4.0.2 Yes
Application oracle mysql 4.0.3 Yes
Application oracle mysql 4.0.4 Yes
Application oracle mysql 4.0.5 Yes
Application oracle mysql 4.0.5a Yes
Application oracle mysql 4.0.6 Yes
Application oracle mysql 4.0.7 Yes
Application oracle mysql 4.0.7 Yes
Application oracle mysql 4.0.8 Yes
Application oracle mysql 4.0.8 Yes
Application oracle mysql 4.0.9 Yes
Application oracle mysql 4.0.9 Yes
Application oracle mysql 4.0.10 Yes
Application oracle mysql 4.0.11 Yes
Application oracle mysql 4.0.11 Yes
Application oracle mysql 4.0.12 Yes
Application oracle mysql 4.0.13 Yes
Application oracle mysql 4.0.14 Yes
Application oracle mysql 4.0.15 Yes
Application oracle mysql 4.0.16 Yes
Application oracle mysql 4.0.17 Yes
Application oracle mysql 4.0.18 Yes
Application oracle mysql 4.0.19 Yes
Application oracle mysql 4.0.20 Yes
Application oracle mysql 4.0.21 Yes
Application oracle mysql 4.0.23 Yes
Application oracle mysql 4.0.24 Yes
Application oracle mysql 4.0.25 Yes
Application oracle mysql 4.0.26 Yes
Application oracle mysql 4.0.27 Yes
Application oracle mysql 4.1.0 Yes
Application oracle mysql 4.1.2 Yes
Application oracle mysql 4.1.3 Yes
Application oracle mysql 4.1.4 Yes
Application oracle mysql 4.1.5 Yes
Application oracle mysql 4.1.6 Yes
Application oracle mysql 4.1.7 Yes
Application oracle mysql 4.1.9 Yes
Application oracle mysql 4.1.11 Yes
Application oracle mysql 4.1.16 Yes
Application oracle mysql 4.1.17 Yes
Application oracle mysql 4.1.18 Yes
Application oracle mysql 4.1.19 Yes
Application oracle mysql 5.0.0 Yes
Application oracle mysql 5.0.3 Yes
Application oracle mysql 5.0.6 Yes
Application oracle mysql 5.0.7 Yes
Application oracle mysql 5.0.8 Yes
Application oracle mysql 5.0.9 Yes
Application oracle mysql 5.0.11 Yes
Application oracle mysql 5.0.12 Yes
Application oracle mysql 5.0.13 Yes
Application oracle mysql 5.0.14 Yes
Application oracle mysql 5.0.18 Yes

References