MySQLDumper 1.21b through 1.23 REV227 uses a Limit GET statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mysqldumper | Mysqldumper | 1.21 (including) | 1.21 (including) |
Mysqldumper | Mysqldumper | 1.22 (including) | 1.22 (including) |
Mysqldumper | Mysqldumper | 1.23 (including) | 1.23 (including) |
Mysqldumper | Mysqldumper | typo3-extension_0.0.5 (including) | typo3-extension_0.0.5 (including) |