6.5
CVSSv2

CVE-2010-1848

Published: 08/06/2010 Updated: 17/12/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in MySQL 5.0 up to and including 5.0.91 and 5.1 prior to 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql 5.0.1

mysql mysql 5.0.10

mysql mysql 5.0.16

mysql mysql 5.0.2

mysql mysql 5.0.20

oracle mysql 5.0.0

oracle mysql 5.0.14

mysql mysql 5.0.15

oracle mysql 5.0.19

mysql mysql 5.0.24

oracle mysql 5.0.45

mysql mysql 5.0.45b

mysql mysql 5.0.82

oracle mysql 5.0.83

mysql mysql 5.0.84

oracle mysql 5.0.91

oracle mysql 5.0.9

oracle mysql 5.0.11

mysql mysql 5.0.17

oracle mysql 5.0.21

oracle mysql 5.0.22

oracle mysql 5.0.3

oracle mysql 5.0.33

oracle mysql 5.0.67

oracle mysql 5.0.75

mysql mysql 5.0.87

oracle mysql 5.0.88

mysql mysql 5.0.5

oracle mysql 5.0.6

oracle mysql 5.0.27

mysql mysql 5.0.3

oracle mysql 5.0.51

oracle mysql 5.0.85

oracle mysql 5.0.86

mysql mysql 5.0.4

mysql mysql 5.0.0

oracle mysql 5.0.12

oracle mysql 5.0.13

oracle mysql 5.0.18

mysql mysql 5.0.5.0.21

oracle mysql 5.0.23

oracle mysql 5.0.37

oracle mysql 5.0.41

oracle mysql 5.0.77

oracle mysql 5.0.81

oracle mysql 5.0.89

oracle mysql 5.0.90

oracle mysql 5.0.7

oracle mysql 5.0.8

oracle mysql 5.1.13

oracle mysql 5.1.14

oracle mysql 5.1.15

mysql mysql 5.1.5

mysql mysql 5.1.31

mysql mysql 5.1.32

oracle mysql 5.1.40

oracle mysql 5.1.41

oracle mysql 5.1.1

oracle mysql 5.1.10

oracle mysql 5.1.2

mysql mysql 5.1.23

oracle mysql 5.1.8

oracle mysql 5.1.9

oracle mysql 5.1.35

oracle mysql 5.1.36

oracle mysql 5.1.44

oracle mysql 5.1.45

oracle mysql 5.1

oracle mysql 5.1.16

oracle mysql 5.1.17

oracle mysql 5.1.6

oracle mysql 5.1.7

oracle mysql 5.1.33

mysql mysql 5.1.34

oracle mysql 5.1.42

oracle mysql 5.1.43

oracle mysql 5.1.11

oracle mysql 5.1.12

oracle mysql 5.1.3

oracle mysql 5.1.4

oracle mysql 5.1.30

mysql mysql 5.1.37

oracle mysql 5.1.38

oracle mysql 5.1.39

oracle mysql 5.1.46

Vendor Advisories

Several vulnerabilities have been discovered in the MySQL database server The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-1626 MySQL allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command CVE-2010-1848 MySQL ...
It was discovered that MySQL did not check privileges before uninstalling plugins An authenticated user could uninstall arbitrary plugins, bypassing intended restrictions This issue only affected Ubuntu 910 and 1004 LTS (CVE-2010-1621) ...