MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-05-01 21:00
Updated : 2019-12-17 09:12
NVD link : CVE-2005-0709
Mitre link : CVE-2005-0709
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
oracle
- mysql
mysql
- mysql