Lucene search

K
nvd[email protected]NVD:CVE-2005-0709
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-0709

2005-05-0204:00:00
CWE-94
web.nvd.nist.gov
3

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.968

Percentile

99.7%

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

Affected configurations

NVD
Node
mysqlmysqlMatch4.1.0
OR
mysqlmysqlMatch4.1.3
OR
mysqlmysqlMatch4.1.10
OR
oraclemysqlMatch3.23.49
OR
oraclemysqlMatch4.0.0
OR
oraclemysqlMatch4.0.1
OR
oraclemysqlMatch4.0.2
OR
oraclemysqlMatch4.0.3
OR
oraclemysqlMatch4.0.4
OR
oraclemysqlMatch4.0.5
OR
oraclemysqlMatch4.0.5a
OR
oraclemysqlMatch4.0.6
OR
oraclemysqlMatch4.0.7
OR
oraclemysqlMatch4.0.7gamma
OR
oraclemysqlMatch4.0.8
OR
oraclemysqlMatch4.0.8gamma
OR
oraclemysqlMatch4.0.9
OR
oraclemysqlMatch4.0.9gamma
OR
oraclemysqlMatch4.0.10
OR
oraclemysqlMatch4.0.11
OR
oraclemysqlMatch4.0.11gamma
OR
oraclemysqlMatch4.0.12
OR
oraclemysqlMatch4.0.13
OR
oraclemysqlMatch4.0.14
OR
oraclemysqlMatch4.0.15
OR
oraclemysqlMatch4.0.18
OR
oraclemysqlMatch4.0.20
OR
oraclemysqlMatch4.0.21
OR
oraclemysqlMatch4.0.23
OR
oraclemysqlMatch4.1.0alpha
OR
oraclemysqlMatch4.1.2alpha
OR
oraclemysqlMatch4.1.3beta
OR
oraclemysqlMatch4.1.4
OR
oraclemysqlMatch4.1.5

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.968

Percentile

99.7%