CVE-2008-4456
Estado: ModificadaBaja (2.6)—💥 Exploit
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el cliente command-line en MySQL v5.0.26 a la v5.0.45, cuando la opción --html está activa, permite a los atacantes inyectar web script o HTML de su elección colocándolo en una celda de la base de datos, a la que puede acceder el cliente al comoponer un documento HTML.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 7.05%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 10/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · MySQL 5 - Command Line Client HTML Special Characters HTML Injection (30/9/2008)
Tecnologías afectadas (2)
CWE
- CWE-79
Referencias
- http://bugs.mysql.com/bug.php?id=27884
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
- http://seclists.org/bugtraq/2008/Oct/0026.html
- http://secunia.com/advisories/32072
- http://secunia.com/advisories/34907
- http://secunia.com/advisories/36566
- http://secunia.com/advisories/38517
- http://securityreason.com/securityalert/4357
- http://support.apple.com/kb/HT4077
- http://ubuntu.com/usn/usn-897-1
- http://www.debian.org/security/2009/dsa-1783
- http://www.henlich.de/it-security/mysql-command-line-client-html-injection-vulnerability
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:094
- http://www.redhat.com/support/errata/RHSA-2009-1289.html
- http://www.redhat.com/support/errata/RHSA-2010-0110.html
- http://www.securityfocus.com/archive/1/496842/100/0/threaded
- http://www.securityfocus.com/archive/1/496877/100/0/threaded
- http://www.securityfocus.com/archive/1/497158/100/0/threaded
- http://www.securityfocus.com/archive/1/497885/100/0/threaded
- http://www.securityfocus.com/bid/31486
- http://www.ubuntu.com/usn/USN-1397-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45590
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11456
- http://bugs.mysql.com/bug.php?id=27884
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
- http://seclists.org/bugtraq/2008/Oct/0026.html
- http://secunia.com/advisories/32072
- http://secunia.com/advisories/34907
- http://secunia.com/advisories/36566
- http://secunia.com/advisories/38517
- http://securityreason.com/securityalert/4357
- http://support.apple.com/kb/HT4077
- http://ubuntu.com/usn/usn-897-1
- http://www.debian.org/security/2009/dsa-1783
- http://www.henlich.de/it-security/mysql-command-line-client-html-injection-vulnerability
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:094
- http://www.redhat.com/support/errata/RHSA-2009-1289.html
- http://www.redhat.com/support/errata/RHSA-2010-0110.html
- http://www.securityfocus.com/archive/1/496842/100/0/threaded
- http://www.securityfocus.com/archive/1/496877/100/0/threaded
- http://www.securityfocus.com/archive/1/497158/100/0/threaded
- http://www.securityfocus.com/archive/1/497885/100/0/threaded
- http://www.securityfocus.com/bid/31486
- http://www.ubuntu.com/usn/USN-1397-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45590
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11456
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4456",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-10-06T23:25:50.707",
"references": [
{
"url": "http://bugs.mysql.com/bug.php?id=27884",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/bugtraq/2008/Oct/0026.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/32072",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/34907",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/36566",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/38517",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/4357",
"source": "cve@mitre.org"
},
{
"url": "http://support.apple.com/kb/HT4077",
"source": "cve@mitre.org"
},
{
"url": "http://ubuntu.com/usn/usn-897-1",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2009/dsa-1783",
"source": "cve@mitre.org"
},
{
"url": "http://www.henlich.de/it-security/mysql-command-line-client-html-injection-vulnerability",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:094",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2009-1289.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0110.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/496842/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/496877/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/497158/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/497885/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/31486",
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/USN-1397-1",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45590",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11456",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.mysql.com/bug.php?id=27884",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/bugtraq/2008/Oct/0026.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32072",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/34907",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/36566",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/38517",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/4357",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT4077",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://ubuntu.com/usn/usn-897-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2009/dsa-1783",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.henlich.de/it-security/mysql-command-line-client-html-injection-vulnerability",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:094",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2009-1289.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0110.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/496842/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/496877/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/497158/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/497885/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/31486",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1397-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45590",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11456",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el cliente command-line en MySQL v5.0.26 a la v5.0.45, cuando la opción --html está activa, permite a los atacantes inyectar web script o HTML de su elección colocándolo en una celda de la base de datos, a la que puede acceder el cliente al comoponer un documento HTML."
}
],
"lastModified": "2026-06-16T22:57:50.650",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "754B78F2-A03C-40BE-812B-F5E57B93D20B"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BEF9271A-A816-44F6-A811-ECC1FB0993C5"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.36:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F482D3D3-205C-495E-AF3A-E9C3018111F7"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.44:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53853D65-F2C6-410F-9CF8-DED19B66BD4E"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.26:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "811780EA-8805-41A6-A920-A201CCC80790"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.27:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11873AEA-5D6C-4AC0-915A-8A2869B2EFF5"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.30:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7753CE5-61C4-4FBC-BB60-F7D4493E76E3"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7EDC2EB4-2C8D-4EF7-83A6-CBE6FF759DD0"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.33:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5965032E-5BC0-4E69-B097-F9EE2B24C861"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.37:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35F21A5A-F9C0-4860-80AD-1D3937483F28"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.38:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B54F660F-AE43-4F3B-8935-5712CAE860A9"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.41:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4413BB52-6FBD-4C12-8864-ADDC65E45B25"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.42:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B49F9BA-560B-40AE-9457-436830CDD371"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.45:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F53A8437-C61A-4203-B341-B5596569E50B"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.67:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C98C5EFF-B629-4FFF-B535-0C25DADD1C25"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-4456\n\nThis issue was addressed for Red Hat Enterprise Linux 5 by https://rhn.redhat.com/errata/RHSA-2009-1289.html and Red Hat Enterprise Linux 4 by https://rhn.redhat.com/errata/RHSA-2010-0110.html .\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, future MySQL package updates may address this flaw for Red Hat Enterprise Linux 3, and Red Hat Application Stack 2.",
"lastModified": "2010-02-17T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}