Greensql develops a database security and firewall product line designed to protect SQL databases and web applications from injection and input-handling attacks. The recurring weakness classes in its disclosure record—cross-site scripting, SQL injection, and related input-validation flaws—reflect the application-layer and database-query inspection that its platform is intended to address. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Greensql over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6992HIGH GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expressio | Aug 19, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-7229HIGH GreenSQL Firewall (greensql-fw) before 0.9.2 allows remote attackers to bypass SQL injection protection via a crafted string, possibly involving an encoded space character (%20). | Sep 14, 2009 | 7.5 | 19 | NO | NO |
CVE-2007-5059MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL allow remote attackers to inject arbitrary web script or HTML via several vectors, as demonstrated by the (1) uname | Sep 24, 2007 | 4.3 | 16 | NO | NO |
CVE-2008-6417MEDIUM Unspecified vulnerability in GreenSQL-Console before 0.3.5 allows attackers to obtain the "installation directory" via unknown vectors. | Mar 6, 2009 | 5.0 | 15 | NO | NO |
CVE-2008-6416MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL-Console before 0.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related t | Mar 6, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Greensql.
Media articles that mention a CVE ID that affects a product developed by Greensql — matched by CVE ID, not by vendor name.