cbcvebase.
CVE-2005-1636
published 2005-05-17

CVE-2005-1636: mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions…

PriorityP422medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.61%
45.5th percentile
mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.

Affected

18 ranges
VendorProductVersion rangeFixed in
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql
oraclemysql

CVSS provenance

nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.