← Back

CVE-2005-2573

nvd nist
Published: Aug 16, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.

Affected (38)

Products: Mysql: Mysql · Oracle: Mysql
1 product
Mysql
1 product
Mysql
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Mysql
Version 4.1.0
Version 4.1.10
Version 4.1.3
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Oracle
Version 4.0.0
Version 4.0.10
Version 4.0.11
Version 4.0.11 gamma
Version 4.0.12
Version 4.0.13
Version 4.0.14
Version 4.0.15
Version 4.0.18
Version 4.0.1
Version 4.0.20
Version 4.0.21
Version 4.0.24
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.5a
Version 4.0.6
Version 4.0.7
Version 4.0.7 gamma
Version 4.0.8
Version 4.0.8 gamma
Version 4.0.9
Version 4.0.9 gamma
Version 4.1.0 alpha
Version 4.1.2 alpha
Version 4.1.3 beta
Version 4.1.4
Version 4.1.5
Version 5.0.0 alpha

Timeline

No history available yet.