vendor:
MySQL
by:
SecurityFocus
7.5
CVSS
HIGH
Privilege-Elevation and Security-Bypass
264, 287
CWE
Product Name: MySQL
Affected Version From: 5.0.24
Affected Version To: 5.0.24
Patch Exists: YES
Related CWE: N/A
CPE: a:mysql:mysql
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
MySQL Privilege-Elevation and Security-Bypass Vulnerabilities
MySQL is prone to a privilege-elevation vulnerability and a security-bypass vulnerability. A user with privileges to execute SUID routines may gain elevated privileges by executing certain commands and code with higher privileges. A user can also bypass restrictions and create new databases. MySQL 5.0.24 and prior versions are affected by these issues.
Mitigation:
Upgrade to the latest version of MySQL, or apply the appropriate patch.