VYPR
Critical severityNVD Advisory· Published Mar 14, 2011· Updated Apr 29, 2026

CVE-2011-0432

CVE-2011-0432

Description

Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pywebdavPyPI
< 0.9.4.10.9.4.1

Affected products

10
  • cpe:2.3:a:simon_pamies:pywebdav:*:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:simon_pamies:pywebdav:*:*:*:*:*:*:*:*range: <=0.9.4
    • cpe:2.3:a:simon_pamies:pywebdav:0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:simon_pamies:pywebdav:0.9.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

21

News mentions

0

No linked articles in our index yet.