PT-2005-3464 · Oracle · Mysql Server
Reid Borsuk
·
Publicado
2005-08-16
·
Atualizado
2019-12-17
·
CVE-2005-2573
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MySQL versions 4.0 through 4.0.24
MySQL versions 4.1 through 4.1.12
MySQL versions 5.0 through 5.0.6-beta
Description
The issue arises from an incomplete blacklist used in a directory traversal check within the
mysql create function function. This allows attackers to include arbitrary files using the backslash (``) character when running on Windows.Recommendations
For MySQL versions 4.0 through 4.0.24, update to version 4.0.25 or later.
For MySQL versions 4.1 through 4.1.12, update to version 4.1.13 or later.
For MySQL versions 5.0 through 5.0.6-beta, update to version 5.0.7-beta or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mysql Server