← Back

CVE-2005-1636

nvd nist
Published: May 17, 2005Modified: Apr 16, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.

Affected (22)

Products: Mysql: Mysql · Oracle: Mysql
1 product
Mysql
1 product
Mysql
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Mysql
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Oracle
Version 4.0.0
Version 4.0.10
Version 4.0.11
Version 4.0.11 gamma
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.5a
Version 4.0.6
Version 4.0.7
Version 4.0.7 gamma
Version 4.0.8
Version 4.0.8 gamma
Version 4.0.9
Version 4.0.9 gamma
Version 5.0.0 alpha

References (18)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.