Hey all,
It was brought to our attention today that Cybertrust scanning of our web interfaces may have revealed a vulnerability that would allow malicious mysql statements to be executed should somebody so desire. While it’s believed this is a false positive, we are curious as to whether or not anybody has explored the issue of such a vulnerability in the web server, and most specifically whether or not this has been addressed in any way (patch, confirmation that we are not vulnerable, etc.). We are on 5.7.1 on a solaris platform.
Any input is appreciated!
All the best,
Tony



