SQL Injection Vulnerability in mod_authnz_external 3.2.5 and Earlier: Remote Code Execution via User Field

SQL Injection Vulnerability in mod_authnz_external 3.2.5 and Earlier: Remote Code Execution via User Field

CVE-2011-2688 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.

Learn more about our Cis Benchmark Audit For Apache Http Server.