PT-2004-1897 · Oracle · Mysql Server
Oleksandr Byelkin
·
Publicado
2004-10-16
·
Atualizado
2019-10-07
·
CVE-2004-0835
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
MySQL versions 3.x through 3.23.58
MySQL versions 4.x through 4.0.18
MySQL versions 4.1.x through 4.1.1
MySQL versions 5.x through 5.0.0
Description:
The issue allows attackers to conduct unauthorized activities by checking the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation.
Recommendations:
For MySQL versions 3.x through 3.23.58, update to version 3.23.59 or later.
For MySQL versions 4.x through 4.0.18, update to version 4.0.19 or later.
For MySQL versions 4.1.x through 4.1.1, update to version 4.1.2 or later.
For MySQL versions 5.x through 5.0.0, update to version 5.0.1 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mysql Server