Back

MEDIUM

php: mysqli mysqli_fetch_assoc does not escape its output when magic_quotes are enabled

Published Jan 18, 2011

Description

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 4, 5, or 6.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 18, 2011
Updated Aug 7, 2024
Reserved Jan 18, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 1, 2010