Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2006-7232

LOW severity · CVSS 3.5 · SQL injection
3.5CVSS LOW

Summary

sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.

Impact & exploitability

Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)2%

AV:N/AC:M/Au:S/C:N/I:N/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://bugs.mysql.com/bug.php?id=22413 ↗