CVE-2009-1208
auth2db 0.2.5 - SQL Injection via Multibyte Character Encoding
Title source: llmDescription
SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/34287
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34488
Patch vendor-advisory
x_refsource_debian
http://www.debian.org/security/2009/dsa-1757
Patch x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521823
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49518
Various Sources x_refsource_confirm
http://www.auth2db.com.ar/?title=CHANGELOG
Scores
EPSS
0.0196
EPSS Percentile
78.2%
Details
CWE
CWE-89
Status
published
Products (17)
auth2db/auth2db
0.1.0
auth2db/auth2db
0.1.2
auth2db/auth2db
0.1.3
auth2db/auth2db
0.1.4
auth2db/auth2db
0.1.5
auth2db/auth2db
0.1.6
auth2db/auth2db
0.1.7
auth2db/auth2db
0.1.8
auth2db/auth2db
0.1.9
auth2db/auth2db
0.2.0
... and 7 more
Published
Apr 01, 2009
Tracked Since
Feb 18, 2026