CVE-2017-11509

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
28/03/2018
Last modified:
23/11/2021

Description

An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:firebirdsql:firebird:2.5.7:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:3.0.2:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*