7.1

CVE-2007-5969

Exploit

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

Data is provided by the National Vulnerability Database (NVD)
MysqlMysql Server Version5.1.22
MysqlMysql Server Version6.0
MysqlMysql Server Version6.0.1
MysqlMysql Server Version6.0.2
MysqlMysql Server Version6.0.3
MysqlCommunity Server Version <= 5.0.50
MysqlCommunity Server Version5.0.41
MysqlCommunity Server Version5.0.44
MysqlCommunity Server Version5.0.45
MysqlMysql Enterprise Server Version5.0.50
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.28% 0.784
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.1 3.9 10
AV:N/AC:H/Au:S/C:C/I:C/A:C
http://lists.mysql.com/announce/495
Vendor Advisory
Exploit