CVE-2006-4226
published 2006-08-18CVE-2006-4226: MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a…
PriorityP415low3.6CVSS 2.0
AVNACHAuSCPIPAN
EPSS
2.81%
84.9th percentile
MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.
Affected
91 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.03.6LOWAV:N/AC:H/Au:S/C:P/I:P/A:N
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql-server create database privilege escalation
vendor_redhat·2006-02-22·CVSS 3.6
CVE-2006-4226 [LOW] mysql-server create database privilege escalation
mysql-server create database privilege escalation
MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.
Statement: This issue does not affect Red Hat Enterprise Linux 2.1 or 3
GHSA
GHSA-g59j-2mhw-4h6x: MySQL before 4
ghsa_unreviewed·2022-05-01
CVE-2006-4226 [LOW] GHSA-g59j-2mhw-4h6x: MySQL before 4
MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.mysql.com/bug.php?id=17647http://dev.mysql.com/doc/refman/5.0/en/news-5-0-25.htmlhttp://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://lists.mysql.com/commits/5927http://secunia.com/advisories/21506http://secunia.com/advisories/21627http://secunia.com/advisories/21762http://secunia.com/advisories/22080http://secunia.com/advisories/24479http://secunia.com/advisories/24744http://securitytracker.com/id?1016710http://www.debian.org/security/2006/dsa-1169http://www.mandriva.com/security/advisories?name=MDKSA-2006:149http://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0083.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0152.htmlhttp://www.securityfocus.com/bid/19559http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2006/3306http://www.vupen.com/english/advisories/2007/0930https://exchange.xforce.ibmcloud.com/vulnerabilities/28448https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10729http://bugs.mysql.com/bug.php?id=17647http://dev.mysql.com/doc/refman/5.0/en/news-5-0-25.htmlhttp://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://lists.mysql.com/commits/5927http://secunia.com/advisories/21506http://secunia.com/advisories/21627http://secunia.com/advisories/21762http://secunia.com/advisories/22080http://secunia.com/advisories/24479http://secunia.com/advisories/24744http://securitytracker.com/id?1016710http://www.debian.org/security/2006/dsa-1169http://www.mandriva.com/security/advisories?name=MDKSA-2006:149http://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0083.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0152.htmlhttp://www.securityfocus.com/bid/19559http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2006/3306http://www.vupen.com/english/advisories/2007/0930https://exchange.xforce.ibmcloud.com/vulnerabilities/28448https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10729
2006-08-18
Published