Definition


New Search

Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability

oval:org.mitre.oval:def:7210

Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables and on 5.1 to read or delete content of arbitrary tables via a .. (dot dot) in a table name.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2003
  • Microsoft Windows Vista
  • Microsoft Windows Server 2008
  • Microsoft Windows XP
  • Microsoft Windows 7
  • Microsoft Windows 2000
Class:
vulnerability
Reference(s):
  • CVE-2010-1848
Product(s):
  • MySQL Server 5.1
  • MySQL Server 5.0