PyPI: pywebdav
CVE-2011-0432
Safety vulnerability ID: SFTY-20110314-21338
Safety legacy ID: pyup.io-42234
Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.
Overview
PyWebDAV SQL Injection vulnerability
Advisory
Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20110314-21338/CVE-2011-0432
- http://code.google.com/p/pywebdav/updates/list
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055412.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055413.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055444.html
- http://pywebdav.googlecode.com/files/PyWebDAV-0.9.4.1.tar.gz
- http://secunia.com/advisories/43571
- http://secunia.com/advisories/43602
- http://secunia.com/advisories/43703
- http://www.debian.org/security/2011/dsa-2177
- http://www.securityfocus.com/bid/46655
- http://www.vupen.com/english/advisories/2011/0553
- http://www.vupen.com/english/advisories/2011/0554
- http://www.vupen.com/english/advisories/2011/0634
- https://bugzilla.redhat.com/show_bug.cgi?id=677718
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0432
- https://nvd.nist.gov/vuln/detail/CVE-2011-0432
- https://bugzilla.redhat.com/show_bug.cgi?id=677718
- http://code.google.com/p/pywebdav/updates/list
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055412.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055413.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055444.html
- http://pywebdav.googlecode.com/files/PyWebDAV-0.9.4.1.tar.gz
- https://web.archive.org/web/20110305233800/http://secunia.com/advisories/43571
- https://web.archive.org/web/20110321033933/http://secunia.com/advisories/43602
- https://web.archive.org/web/20110321055414/http://secunia.com/advisories/43703
- https://web.archive.org/web/20200228163209/http://www.securityfocus.com/bid/46655
- https://github.com/pypa/advisory-database/tree/main/vulns/pywebdav/PYSEC-2011-7.yaml
- https://github.com/advisories/GHSA-69vw-jfq7-935g
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
