Show filters
160 Total Results
Displaying 111-120 of 160
Sort by:
Attacker Value
Unknown

CVE-2007-3567

Disclosure Date: July 05, 2007 (last updated October 04, 2023)
MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.
0
Attacker Value
Unknown

CVE-2007-2692

Disclosure Date: May 16, 2007 (last updated October 04, 2023)
The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.
0
Attacker Value
Unknown

CVE-2007-2693

Disclosure Date: May 16, 2007 (last updated October 04, 2023)
MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
0
Attacker Value
Unknown

CVE-2007-2691

Disclosure Date: May 16, 2007 (last updated October 04, 2023)
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
0
Attacker Value
Unknown

CVE-2007-1420

Disclosure Date: March 12, 2007 (last updated October 04, 2023)
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.
0
Attacker Value
Unknown

CVE-2007-0828

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.
0
Attacker Value
Unknown

CVE-2006-7232

Disclosure Date: December 31, 2006 (last updated October 04, 2023)
sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.
0
Attacker Value
Unknown

CVE-2006-5264

Disclosure Date: October 12, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter.
0
Attacker Value
Unknown

CVE-2006-4305

Disclosure Date: August 30, 2006 (last updated October 04, 2023)
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client.
0
Attacker Value
Unknown

CVE-2006-4380

Disclosure Date: August 28, 2006 (last updated October 04, 2023)
MySQL before 4.1.13 allows local users to cause a denial of service (persistent replication slave crash) via a query with multiupdate and subselects.
0