Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-0835

Опубликовано: 03 нояб. 2004
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.2 (включая)
cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.1 (включая)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
Версия от 3.20 (исключая) до 3.23.59 (исключая)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.19 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.22352
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 21 года назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

redhat
больше 22 лет назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

debian
больше 21 года назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5 ...

github
больше 4 лет назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

EPSS

Процентиль: 97%
0.22352
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other