CVE-2005-0710
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 13%
from disclosure to weapon0 days
Published on NVDMar 11
1st PoCMar 11
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/25210⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0083.htmlhttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlhttp://marc.info/?l=bugtraq&m=111065974004648&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/19658https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10180http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1https://usn.ubuntu.com/96-1/http://www.debian.org/security/2005/dsa-707http://www.gentoo.org/security/en/glsa/glsa-200503-19.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:060http://www.novell.com/linux/security/advisories/2005_19_mysql.html