7.5
CVSSv2

CVE-2008-6992

Published: 19/08/2009 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

GreenSQL Firewall (greensql-fw), possibly prior to 0.9.2 or 0.9.4, allows remote malicious users to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.

Vulnerable Product Search on Vulmon Subscribe to Product

greensql greensql firewall 0.3.4

greensql greensql firewall

greensql greensql firewall 0.3.5

greensql greensql firewall 0.8.2

Exploits

source: wwwsecurityfocuscom/bid/36209/info GreenSQL Firewall is prone to a security-bypass vulnerability An attacker can exploit this issue to bypass certain security restrictions Successfully exploiting this issue may aid in SQL attacks on the underlying application The following sample SQL expression is available: x=y=z ...