MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2007-05-15 18:19
Updated : 2018-10-19 12:00
NVD link : CVE-2007-2691
Mitre link : CVE-2007-2691
JSON object : View
CWE
Products Affected
debian
- debian_linux
canonical
- ubuntu_linux
mysql
- mysql