CVE-2006-7232

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
31/12/2006
Last modified:
09/04/2025

Description

sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* 5.0 (including) 5.0.32 (excluding)
cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* 5.1 (including) 5.1.14 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*