PoC Index

CVE-2006-4227

MEDIUM 6.5EPSS 12.5%

MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
12.47% chance of exploitation in the next 30 days, 96th percentile
Published
2006-08-18
Updated
2024-08-07

ExploitDB entries (1)

References

Related