CVE-2005-0709
MEDIUM 4.6EPSS 18.4%
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
- CVSS v2.0
- 4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 18.44% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2005-03-11
- Updated
- 2024-08-07