info
discussion
exploit
solution
references
MySQL Command Line Client HTML Special Characters HTML Injection Vulnerability
References:
Bug #27884 mysql --html does not quote HTML special characters in output
(Thomas Henlich)
MySQL command-line client HTML injection vulnerability
(Henlich schreibt)
MySQL Homepage
(Oracle)
MySQL command-line client HTML injection vulnerability
(Thomas Henlich
)
RHSA-2010:0110 mysql security update
(Red Hat)
Ubuntu Security Notice USN-897-1
(Ubuntu)
Privacy Statement
Copyright 2010, SecurityFocus