[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2003-0150Date: (C)2003-03-24   (M)2023-12-22


MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.0
Exploit Score: 8.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication:
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://marc.info/?l=bugtraq&m=104715840202315&w=2
http://marc.info/?l=bugtraq&m=104739810523433&w=2
http://marc.info/?l=bugtraq&m=104802285012750&w=2
http://marc.info/?l=bugtraq&m=104800948128630&w=2
BID-7052
CLA-2003:743
DSA-303
ESA-20030324-012
MDKSA-2003:057
RHSA-2003:093
RHSA-2003:094
VU#203897
mysql-datadir-root-privileges(11510)

© SecPod Technologies