CVE-2011-0432

Publication date 14 March 2011

Last updated 24 July 2024


Ubuntu priority

Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
pywebdav 13.10 saucy
Not affected
13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Fixed 0.9.4-1+squeeze1build0.10.10.1
10.04 LTS lucid Ignored end of life
9.10 karmic Ignored end of life
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release