CVE-2011-2688
libapache2-mod-authnz-external - SQL injection
EPSS 5.7%
Description
SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
How to fix CVE-2011-2688
To remediate CVE-2011-2688, upgrade the affected package to a fixed version below.
- Debian/libapache2-mod-authnz-external—upgrade to 3.2.4-2.1 or later
- Debian/libapache2-mod-authnz-external—upgrade to 3.2.4-2+squeeze1 or later
Is CVE-2011-2688 being exploited?
Moderate — EPSS is 5.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 3.2.4-2.1
- from 0, < 3.2.4-2+squeeze1