Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0709Code Injection in Mysql

CWE-94Code Injection7 documents6 sources
Severity
4.6MEDIUMNVD
EPSS
17.9%
top 4.83%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

NVDmysql/mysql4.1.0, 4.1.10, 4.1.3+2
NVDoracle/mysql27 versions+26

Patches

🔴Vulnerability Details

1
GHSA
GHSA-3x8w-p58r-45ff: MySQL 42022-05-01

💥Exploits & PoCs

1
Exploit-DB
MySQL 4.x - CREATE FUNCTION Arbitrary libc Code Execution2005-03-11

📋Vendor Advisories

2
Ubuntu
mySQL vulnerabilities2005-03-16
Red Hat
security flaw2005-03-11

💬Community

1
Bugzilla
CVE-2005-0709 security flaw2018-08-16
CVE-2005-0709 — Code Injection in Mysql | cvebase