Multiple SQL injection vulnerabilities in the get_userinfo
method in the MySQLAuthHandler class in DAVServer/mysqlauth.py
in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.
{ "nvd_published_at": "2011-03-14T19:55:00Z", "cwe_ids": [ "CWE-89" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-01T16:32:51Z" }