New Search

Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability

oval:org.mitre.oval:def:7210

Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables and on 5.1 to read or delete content of arbitrary tables via a .. (dot dot) in a table name.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 7
  • Microsoft Windows XP
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2003
  • Microsoft Windows 2000
  • Microsoft Windows Vista
Class:
vulnerability
Reference(s):
  • CVE-2010-1848
Product(s):
  • MySQL Server 5.0
  • MySQL Server 5.1