CVE Vulnerabilities

CVE-2007-2691

Published: May 16, 2007 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

Affected Software

Name Vendor Start Version End Version
Mysql Mysql * 4.1.22 (including)
Mysql Mysql 5.0 (including) 5.0.42 (excluding)
Mysql Mysql 5.1 (including) 5.1.18 (excluding)

References