The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pam_mysql | Pam_mysql | 0.1 (including) | 0.1 (including) |
Pam_mysql | Pam_mysql | 0.2 (including) | 0.2 (including) |
Pam_mysql | Pam_mysql | 0.3 (including) | 0.3 (including) |
Pam_mysql | Pam_mysql | 0.4 (including) | 0.4 (including) |