PoC Index

CVE-2008-2079

MEDIUM 4.6EPSS 2.6%

MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.

CVSS v2.0
4.6 MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
EPSS
2.59% chance of exploitation in the next 30 days, 84th percentile
Published
2008-05-05
Updated
2024-08-07

Proof-of-concept exploits (1)

References

Related