Show filters
160 Total Results
Displaying 41-50 of 160
Sort by:
Attacker Value
Unknown
CVE-2012-2102
Disclosure Date: August 17, 2012 (last updated October 04, 2023)
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
0
Attacker Value
Unknown
CVE-2009-5026
Disclosure Date: August 17, 2012 (last updated October 04, 2023)
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
0
Attacker Value
Unknown
CVE-2012-2749
Disclosure Date: August 17, 2012 (last updated October 04, 2023)
MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
0
Attacker Value
Unknown
CVE-2012-4253
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.
0
Attacker Value
Unknown
CVE-2012-4252
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.
0
Attacker Value
Unknown
CVE-2012-4254
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
0
Attacker Value
Unknown
CVE-2012-4255
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2012-4251
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
0
Attacker Value
Unknown
CVE-2012-0583
Disclosure Date: May 03, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.
0
Attacker Value
Unknown
CVE-2012-1696
Disclosure Date: May 03, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
0