7.5

CVE-2004-0835

Exploit

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

Data is provided by the National Vulnerability Database (NVD)
MysqlMysql Version >= 4.1.0 <= 4.1.2
MysqlMysql Version >= 5.0.0 <= 5.0.1
OracleMysql Version > 3.20 < 3.23.59
OracleMysql Version >= 4.0.0 < 4.0.19
DebianDebian Linux Version3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.65% 0.867
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P