CVE Vulnerabilities

CVE-2005-2573

Published: Aug 16, 2005 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash () character.

Affected Software

Name Vendor Start Version End Version
Mysql Mysql 4.1.0 (including) 4.1.0 (including)
Mysql Mysql 4.1.3 (including) 4.1.3 (including)
Mysql Mysql 4.1.10 (including) 4.1.10 (including)
Mysql Mysql 5.0.1 (including) 5.0.1 (including)
Mysql Mysql 5.0.2 (including) 5.0.2 (including)
Mysql Mysql 5.0.3 (including) 5.0.3 (including)
Mysql Mysql 5.0.4 (including) 5.0.4 (including)
Mysql Oracle 4.0.0 (including) 4.0.0 (including)
Mysql Oracle 4.0.1 (including) 4.0.1 (including)
Mysql Oracle 4.0.2 (including) 4.0.2 (including)
Mysql Oracle 4.0.3 (including) 4.0.3 (including)
Mysql Oracle 4.0.4 (including) 4.0.4 (including)
Mysql Oracle 4.0.5 (including) 4.0.5 (including)
Mysql Oracle 4.0.5a (including) 4.0.5a (including)
Mysql Oracle 4.0.6 (including) 4.0.6 (including)
Mysql Oracle 4.0.7 (including) 4.0.7 (including)
Mysql Oracle 4.0.7-gamma (including) 4.0.7-gamma (including)
Mysql Oracle 4.0.8 (including) 4.0.8 (including)
Mysql Oracle 4.0.8-gamma (including) 4.0.8-gamma (including)
Mysql Oracle 4.0.9 (including) 4.0.9 (including)
Mysql Oracle 4.0.9-gamma (including) 4.0.9-gamma (including)
Mysql Oracle 4.0.10 (including) 4.0.10 (including)
Mysql Oracle 4.0.11 (including) 4.0.11 (including)
Mysql Oracle 4.0.11-gamma (including) 4.0.11-gamma (including)
Mysql Oracle 4.0.12 (including) 4.0.12 (including)
Mysql Oracle 4.0.13 (including) 4.0.13 (including)
Mysql Oracle 4.0.14 (including) 4.0.14 (including)
Mysql Oracle 4.0.15 (including) 4.0.15 (including)
Mysql Oracle 4.0.18 (including) 4.0.18 (including)
Mysql Oracle 4.0.20 (including) 4.0.20 (including)
Mysql Oracle 4.0.21 (including) 4.0.21 (including)
Mysql Oracle 4.0.24 (including) 4.0.24 (including)
Mysql Oracle 4.1.0-alpha (including) 4.1.0-alpha (including)
Mysql Oracle 4.1.2-alpha (including) 4.1.2-alpha (including)
Mysql Oracle 4.1.3-beta (including) 4.1.3-beta (including)
Mysql Oracle 4.1.4 (including) 4.1.4 (including)
Mysql Oracle 4.1.5 (including) 4.1.5 (including)
Mysql Oracle 5.0.0-alpha (including) 5.0.0-alpha (including)

References