CVE Vulnerabilities

CVE-2007-2691

Published: May 16, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

Affected Software

NameVendorStart VersionEnd Version
MysqlMysql*4.1.22 (including)
MysqlMysql5.0 (including)5.0.42 (excluding)
MysqlMysql5.1 (including)5.1.18 (excluding)
Red Hat Enterprise Linux 4RedHatmysql-0:4.1.22-2.el4*
Red Hat Enterprise Linux 5RedHatmysql-0:5.0.45-7.el5*
Red Hat Web Application Stack for RHEL 4RedHatmysql-0:5.0.44-1.el4s1.1*
Mysql-dfsg-5.0Ubuntudapper*
Mysql-dfsg-5.0Ubuntudevel*
Mysql-dfsg-5.0Ubuntuedgy*
Mysql-dfsg-5.0Ubuntufeisty*
Mysql-dfsg-5.0Ubuntuupstream*

References