5
CVSSv2

CVE-2010-1621

Published: 14/05/2010 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 prior to 5.1.46 does not check privileges before uninstalling a plugin, which allows remote malicious users to uninstall arbitrary plugins via the UNINSTALL PLUGIN command.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql

Vendor Advisories

It was discovered that MySQL did not check privileges before uninstalling plugins An authenticated user could uninstall arbitrary plugins, bypassing intended restrictions This issue only affected Ubuntu 910 and 1004 LTS (CVE-2010-1621) ...