MariaDB Connector/J 用于将 Java 开发的应用程序连接到 MariaDB 和 MySQL 数据库。在 2.7.14、3.3.5、3.4.3 和 3.5.9 之前的版本中, 在处理服务器发起的 LOCAL INFILE 协议数据包(0xfb)时,未强制应用 配置。当应用程序发送 的 COM_QUERY 命令时,恶意服务器或中间人(Man-in-the-Middle)攻击者可以回显相同的文件名,导致连接器在已禁用该选项的情况下仍然传输该文件。需要注意的是,服务器无法将请求重定向到任意路径,只能接收
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mariadb-corporation | mariadb-connector-j | < 2.7.14 |
affected |
>= 3.0.0, < 3.3.5 |
affected | ||
>= 3.4.0, < 3.4.3 |
affected | ||
>= 3.5.0, < 3.5.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mariadb-corporation | mariadb-connector-j | < 2.7.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet