4
CVSSv2

CVE-2007-3781

Published: 15/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

MySQL Community Server prior to 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql community server 5.0.41

mysql community server 5.0.44

Vendor Advisories

Joe Gallo and Artem Russakovskii discovered that the InnoDB engine in MySQL did not properly perform input validation An authenticated user could use a crafted CONTAINS statement to cause a denial of service (CVE-2007-5925) ...
Several local/remote vulnerabilities have been discovered in the MySQL database server The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-3781 It was discovered that the privilege validation for the source table of CREATE TABLE LIKE statements was insufficiently enforced, which might lea ...