Unrated severityNVD Advisory· Published Aug 19, 2009· Updated Apr 23, 2026
CVE-2008-6992
CVE-2008-6992
Description
GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.
Affected products
4cpe:2.3:a:greensql:greensql_firewall:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:greensql:greensql_firewall:*:*:*:*:*:*:*:*range: <=0.8.3
- cpe:2.3:a:greensql:greensql_firewall:0.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:greensql:greensql_firewall:0.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:greensql:greensql_firewall:0.8.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.greensql.net/node/89nvdPatch
- www.greensql.net/node/98nvdPatch
- bugs.mysql.com/bug.phpnvdExploit
- osvdb.org/48910nvdExploit
- www.greensql.net/securitynvdVendor Advisory
- sla.ckers.org/forum/read.phpnvd
News mentions
0No linked articles in our index yet.