5
CVSSv2

CVE-2005-2573

Published: 16/08/2005 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The mysql_create_function function in sql_udf.cc for MySQL 4.0 prior to 4.0.25, 4.1 prior to 4.1.13, and 5.0 prior to 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows malicious users to include arbitrary files via the backslash (\) character.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql 5.0.3

mysql mysql 4.1.10

mysql mysql 5.0.2

mysql mysql 5.0.1

mysql mysql 4.1.0

mysql mysql 5.0.4

mysql mysql 4.1.3

oracle mysql 4.0.0

oracle mysql 4.0.1

oracle mysql 4.0.2

oracle mysql 4.0.3

oracle mysql 4.0.4

oracle mysql 4.0.5

oracle mysql 4.0.5a

oracle mysql 4.0.6

oracle mysql 4.0.7

oracle mysql 4.0.8

oracle mysql 4.0.9

oracle mysql 4.0.10

oracle mysql 4.0.11

oracle mysql 4.0.12

oracle mysql 4.0.13

oracle mysql 4.0.14

oracle mysql 4.0.15

oracle mysql 4.0.18

oracle mysql 4.0.20

oracle mysql 4.0.21

oracle mysql 4.0.24

oracle mysql 4.1.0

oracle mysql 4.1.2

oracle mysql 4.1.3

oracle mysql 4.1.4

oracle mysql 4.1.5

oracle mysql 5.0.0