CVE-2008-2384
mod_auth_mysql: character encoding SQL injection flaw
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
Vulnerabilidad de inyección SQL en mod_auth_mysql.c en el módulo mod-auth-mysql (alias libapache2-mod-auth-mysql) para Apache HTTP Server 2.x, permite a atacantes remotos ejecutar comandos SQL de su elección a través de codificaciones de caracteres multibyte para entradas no especificadas.
SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x allows remote attackers to execute arbitrary SQL commands via multibyte character encodings for unspecified input. This update provides fixes for this vulnerability. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-21 CVE Reserved
- 2009-01-22 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://openwall.com/lists/oss-security/2009/01/21/10 | Mailing List | |
http://secunia.com/advisories/43302 | Third Party Advisory | |
http://www.securityfocus.com/bid/33392 | Vdb Entry | |
http://www.vupen.com/english/advisories/2009/0226 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0367 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48163 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10172 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://klecker.debian.org/~white/mod-auth-mysql/CVE-2008-2384_mod-auth-mysql.patch | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | - | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0 Search vendor "Apache" for product "Http Server" and version "2.0" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.9 Search vendor "Apache" for product "Http Server" and version "2.0.9" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.28 Search vendor "Apache" for product "Http Server" and version "2.0.28" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.28 Search vendor "Apache" for product "Http Server" and version "2.0.28" | beta |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.28 Search vendor "Apache" for product "Http Server" and version "2.0.28" | beta, win32 |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.32 Search vendor "Apache" for product "Http Server" and version "2.0.32" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.32 Search vendor "Apache" for product "Http Server" and version "2.0.32" | beta |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.32 Search vendor "Apache" for product "Http Server" and version "2.0.32" | beta, win32 |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.34 Search vendor "Apache" for product "Http Server" and version "2.0.34" | beta |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.34 Search vendor "Apache" for product "Http Server" and version "2.0.34" | beta, win32 |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.35 Search vendor "Apache" for product "Http Server" and version "2.0.35" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.36 Search vendor "Apache" for product "Http Server" and version "2.0.36" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.37 Search vendor "Apache" for product "Http Server" and version "2.0.37" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.38 Search vendor "Apache" for product "Http Server" and version "2.0.38" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.39 Search vendor "Apache" for product "Http Server" and version "2.0.39" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.40 Search vendor "Apache" for product "Http Server" and version "2.0.40" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.41 Search vendor "Apache" for product "Http Server" and version "2.0.41" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.42 Search vendor "Apache" for product "Http Server" and version "2.0.42" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.43 Search vendor "Apache" for product "Http Server" and version "2.0.43" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.44 Search vendor "Apache" for product "Http Server" and version "2.0.44" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.45 Search vendor "Apache" for product "Http Server" and version "2.0.45" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.46 Search vendor "Apache" for product "Http Server" and version "2.0.46" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.46 Search vendor "Apache" for product "Http Server" and version "2.0.46" | win32 |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.47 Search vendor "Apache" for product "Http Server" and version "2.0.47" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.48 Search vendor "Apache" for product "Http Server" and version "2.0.48" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.49 Search vendor "Apache" for product "Http Server" and version "2.0.49" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.50 Search vendor "Apache" for product "Http Server" and version "2.0.50" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.51 Search vendor "Apache" for product "Http Server" and version "2.0.51" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.52 Search vendor "Apache" for product "Http Server" and version "2.0.52" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.53 Search vendor "Apache" for product "Http Server" and version "2.0.53" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.54 Search vendor "Apache" for product "Http Server" and version "2.0.54" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.55 Search vendor "Apache" for product "Http Server" and version "2.0.55" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.56 Search vendor "Apache" for product "Http Server" and version "2.0.56" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.57 Search vendor "Apache" for product "Http Server" and version "2.0.57" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.58 Search vendor "Apache" for product "Http Server" and version "2.0.58" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.58 Search vendor "Apache" for product "Http Server" and version "2.0.58" | win32 |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.59 Search vendor "Apache" for product "Http Server" and version "2.0.59" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.60 Search vendor "Apache" for product "Http Server" and version "2.0.60" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.0.61 Search vendor "Apache" for product "Http Server" and version "2.0.61" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1 Search vendor "Apache" for product "Http Server" and version "2.1" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.1 Search vendor "Apache" for product "Http Server" and version "2.1.1" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.2 Search vendor "Apache" for product "Http Server" and version "2.1.2" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.3 Search vendor "Apache" for product "Http Server" and version "2.1.3" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.4 Search vendor "Apache" for product "Http Server" and version "2.1.4" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.5 Search vendor "Apache" for product "Http Server" and version "2.1.5" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.6 Search vendor "Apache" for product "Http Server" and version "2.1.6" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.7 Search vendor "Apache" for product "Http Server" and version "2.1.7" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.1.8 Search vendor "Apache" for product "Http Server" and version "2.1.8" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2 Search vendor "Apache" for product "Http Server" and version "2.2" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.0 Search vendor "Apache" for product "Http Server" and version "2.2.0" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.1 Search vendor "Apache" for product "Http Server" and version "2.2.1" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.2 Search vendor "Apache" for product "Http Server" and version "2.2.2" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.2 Search vendor "Apache" for product "Http Server" and version "2.2.2" | windows |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.3 Search vendor "Apache" for product "Http Server" and version "2.2.3" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.3 Search vendor "Apache" for product "Http Server" and version "2.2.3" | windows |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.4 Search vendor "Apache" for product "Http Server" and version "2.2.4" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.2.6 Search vendor "Apache" for product "Http Server" and version "2.2.6" | - |
Safe
|
Joey Schulze Search vendor "Joey Schulze" | Mod Auth Mysql Search vendor "Joey Schulze" for product "Mod Auth Mysql" | * | - |
Affected
| in | Apache Search vendor "Apache" | Http Server Search vendor "Apache" for product "Http Server" | 2.3.0 Search vendor "Apache" for product "Http Server" and version "2.3.0" | - |
Safe
|