CVE Vulnerabilities

CVE-2005-2573

Published: Aug 16, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash () character.

Affected Software

NameVendorStart VersionEnd Version
MysqlMysql4.1.0 (including)4.1.0 (including)
MysqlMysql4.1.3 (including)4.1.3 (including)
MysqlMysql4.1.10 (including)4.1.10 (including)
MysqlMysql5.0.1 (including)5.0.1 (including)
MysqlMysql5.0.2 (including)5.0.2 (including)
MysqlMysql5.0.3 (including)5.0.3 (including)
MysqlMysql5.0.4 (including)5.0.4 (including)
MysqlOracle4.0.0 (including)4.0.0 (including)
MysqlOracle4.0.1 (including)4.0.1 (including)
MysqlOracle4.0.2 (including)4.0.2 (including)
MysqlOracle4.0.3 (including)4.0.3 (including)
MysqlOracle4.0.4 (including)4.0.4 (including)
MysqlOracle4.0.5 (including)4.0.5 (including)
MysqlOracle4.0.5a (including)4.0.5a (including)
MysqlOracle4.0.6 (including)4.0.6 (including)
MysqlOracle4.0.7 (including)4.0.7 (including)
MysqlOracle4.0.7-gamma (including)4.0.7-gamma (including)
MysqlOracle4.0.8 (including)4.0.8 (including)
MysqlOracle4.0.8-gamma (including)4.0.8-gamma (including)
MysqlOracle4.0.9 (including)4.0.9 (including)
MysqlOracle4.0.9-gamma (including)4.0.9-gamma (including)
MysqlOracle4.0.10 (including)4.0.10 (including)
MysqlOracle4.0.11 (including)4.0.11 (including)
MysqlOracle4.0.11-gamma (including)4.0.11-gamma (including)
MysqlOracle4.0.12 (including)4.0.12 (including)
MysqlOracle4.0.13 (including)4.0.13 (including)
MysqlOracle4.0.14 (including)4.0.14 (including)
MysqlOracle4.0.15 (including)4.0.15 (including)
MysqlOracle4.0.18 (including)4.0.18 (including)
MysqlOracle4.0.20 (including)4.0.20 (including)
MysqlOracle4.0.21 (including)4.0.21 (including)
MysqlOracle4.0.24 (including)4.0.24 (including)
MysqlOracle4.1.0-alpha (including)4.1.0-alpha (including)
MysqlOracle4.1.2-alpha (including)4.1.2-alpha (including)
MysqlOracle4.1.3-beta (including)4.1.3-beta (including)
MysqlOracle4.1.4 (including)4.1.4 (including)
MysqlOracle4.1.5 (including)4.1.5 (including)
MysqlOracle5.0.0-alpha (including)5.0.0-alpha (including)

References