PT-2004-1897 · Oracle · Mysql Server
Oleksandr Byelkin
·
Published
2004-10-16
·
Updated
2019-10-07
·
CVE-2004-0835
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
MySQL versions 3.x through 3.23.58
MySQL versions 4.x through 4.0.18
MySQL versions 4.1.x through 4.1.1
MySQL versions 5.x through 5.0.0
Description:
The issue allows attackers to conduct unauthorized activities by checking the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation.
Recommendations:
For MySQL versions 3.x through 3.23.58, update to version 3.23.59 or later.
For MySQL versions 4.x through 4.0.18, update to version 4.0.19 or later.
For MySQL versions 4.1.x through 4.1.1, update to version 4.1.2 or later.
For MySQL versions 5.x through 5.0.0, update to version 5.0.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysql Server