Computer Security
[EN] securityvulns.ru
no-pyccku



See also
  MYSQLQUICKADMIN : MySQL Quick Admin
  MYSQL : MySQL 6.0
  MYSQLDUMPER : MySQLDumper 1.23
  MYSQLCOMMANDER : MySQL Commander 2.7
  BTSAVEMYSQL : BTSaveMySql 1.2
  MYSQLDUMPER : MysqlDumper 1.21
  MYSQL : MySQL 5.1
  PHPMYSQLTIMESHEE : PHP/MYSQL Timesheet 2
  PAMMYSQL : pam_mysql 0.6
  MYSQLAUCTION : MySQL Auction 3.0
Name:MYSQL : MySQL 5.0

 MySQL privilege escalation
updated since 22.07.2008
document It's possible to specify file of different database in CREATE TABLE.
 MySQL SHOW TABLE STATUS DoS
   
 MySQL DoS
document Invalid assertion on CONTAINS processing.
6!MySQL multiple security vulnerabilities
document Denial of service, privilege escalation.
 MySQL multiple security vulnerabilities
document CREATE TABLE LIKE privilege escalation, server crash on authentication.
 MySQL RENAME privilege escalation
document DROP permission is not checked during RENAME operation.
 MySQl database server DoS
document Division by zero and NULL-pointer dereference on malcrafted IF condition.
 MySQL subselect DoS
document NULL pointer dereference if string function is applied to select with "order by" result.
6!Multiple MySQL security vulnerabilities
document Privilege escalation with stored routine, privilege escalation with creating a database with the name different only in case from existing one.
 MySQL MERGE tables privilege escalation
document User may retain acces to MERGE table after access to original table is revoked.
 MySQL DoS
document "select str_to_date( 1, NULL );" request causes database server to crash.
7!Multiple MySQL security vulnerabilities
document Memory content leak during authentication, memory content leak and code execution with COM_TABLE_DUMP packets.
 MySQL information_schema view information leak
document User can discover request used for view regardless of permissions with SELECT * FROM information_schema.views.
6!MySQL buffer overflow
document init_syms function stack-based buffer overflow.
6!MySQL user defined functions multiple vulnerabilities
document Buffer overflow on oversized user defined function name. DoS, directory traversal and privilege escalation on external functions invocation.
 MySQL symbolic links problem
updated since 19.08.2004
document mysqlhotcopy, mysqlaccess unsafe temporary files creation.
7!MySQL unauthorized access
document During password check length of the user-supplied password is used.
 mysqlbug symbolic links problem
document Symbolic links problem during bugreport saving.
                    

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru