Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-0835

Опубликовано: 03 нояб. 2004
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.2 (включая)
cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.1 (включая)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
Версия от 3.20 (исключая) до 3.23.59 (исключая)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.19 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03649
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 20 лет назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

redhat
больше 21 года назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

debian
больше 20 лет назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5 ...

github
около 3 лет назад

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

EPSS

Процентиль: 87%
0.03649
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other