The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Parosproxy | Parosproxy | 3.2.0 (including) | 3.2.0 (including) |
Parosproxy | Parosproxy | 3.2.1 (including) | 3.2.1 (including) |
Parosproxy | Parosproxy | 3.2.2 (including) | 3.2.2 (including) |
Parosproxy | Parosproxy | 3.2.3 (including) | 3.2.3 (including) |
Parosproxy | Parosproxy | 3.2.4 (including) | 3.2.4 (including) |
Parosproxy | Parosproxy | 3.2.5 (including) | 3.2.5 (including) |
Parosproxy | Parosproxy | 3.2.6 (including) | 3.2.6 (including) |