7.1

CVE-2007-5969

Exploit

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MysqlMysql Server Version5.1.22
MysqlMysql Server Version6.0
MysqlMysql Server Version6.0.1
MysqlMysql Server Version6.0.2
MysqlMysql Server Version6.0.3
MysqlCommunity Server Version <= 5.0.50
MysqlCommunity Server Version5.0.41
MysqlCommunity Server Version5.0.44
MysqlCommunity Server Version5.0.45
MysqlMysql Enterprise Server Version5.0.50
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.28% 0.784
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 3.9 10
AV:N/AC:H/Au:S/C:C/I:C/A:C
http://lists.mysql.com/announce/495
Vendor Advisory
Exploit