Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0710Mysql vulnerability

8 documents6 sources
Severity
4.6MEDIUMNVD
EPSS
4.6%
top 10.75%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

NVDmysql/mysql4.1.0, 4.1.10, 4.1.3+2
NVDoracle/mysql27 versions+26

Patches

🔴Vulnerability Details

1
GHSA
GHSA-5wh5-j2hf-hpfc: MySQL 42022-05-01

💥Exploits & PoCs

1
Exploit-DB
MySQL 4.x - CREATE FUNCTION mysql.func Table Arbitrary Library Injection2005-03-11

📋Vendor Advisories

2
Ubuntu
mySQL vulnerabilities2005-03-16
Red Hat
security flaw2005-03-11

💬Community

1
Bugzilla
CVE-2005-0710 security flaw2018-08-16
CVE-2005-0710 — Mysql vulnerability | cvebase