// For flags

CVE-2010-1848

mysql: multiple insufficient table name checks

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.

Vulnerabilidad de salto de directorio en MySQL v5.0 hasta v5.0.91 y v5.1 anteriores a v5.1.47 permite a usuarios autenticados remotamente saltarse tablas establecidas permitiendo leer definiciones de campos de tablas de su elección, y sobre v5.1 leer o eliminar contenido de tablas de su elección, a través de .. (punto punto) en un nombre de tabla.

The server failed to check the table name argument of a COM_FIELD_LIST command packet for validity and compliance to acceptable table name standards. This could be exploited to bypass almost all forms of checks for privileges and table-level grants by providing a specially crafted table name argument to COM_FIELD_LIST. The server could be tricked into reading packets indefinitely if it received a packet larger than the maximum size of one packet. The server was susceptible to a buffer-overflow attack due to a failure to perform bounds checking on the table name argument of a COM_FIELD_LIST command packet. By sending long data for the table name, a buffer is overflown, which could be exploited by an authenticated user to inject malicious code. Packages for 2008.0 and 2009.0 are provided as of the Extended Maintenance Program. The updated packages have been patched to correct these issues.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-05-06 CVE Reserved
  • 2010-05-26 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-07-31 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.0
Search vendor "Mysql" for product "Mysql" and version "5.0.0"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.1
Search vendor "Mysql" for product "Mysql" and version "5.0.1"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.2
Search vendor "Mysql" for product "Mysql" and version "5.0.2"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.3
Search vendor "Mysql" for product "Mysql" and version "5.0.3"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.4
Search vendor "Mysql" for product "Mysql" and version "5.0.4"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.5
Search vendor "Mysql" for product "Mysql" and version "5.0.5"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.5.0.21
Search vendor "Mysql" for product "Mysql" and version "5.0.5.0.21"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.10
Search vendor "Mysql" for product "Mysql" and version "5.0.10"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.15
Search vendor "Mysql" for product "Mysql" and version "5.0.15"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.16
Search vendor "Mysql" for product "Mysql" and version "5.0.16"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.17
Search vendor "Mysql" for product "Mysql" and version "5.0.17"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.20
Search vendor "Mysql" for product "Mysql" and version "5.0.20"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.24
Search vendor "Mysql" for product "Mysql" and version "5.0.24"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.45b
Search vendor "Mysql" for product "Mysql" and version "5.0.45b"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.82
Search vendor "Mysql" for product "Mysql" and version "5.0.82"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.84
Search vendor "Mysql" for product "Mysql" and version "5.0.84"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.87
Search vendor "Mysql" for product "Mysql" and version "5.0.87"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.0
Search vendor "Oracle" for product "Mysql" and version "5.0.0"
alpha
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.3
Search vendor "Oracle" for product "Mysql" and version "5.0.3"
beta
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.6
Search vendor "Oracle" for product "Mysql" and version "5.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.7
Search vendor "Oracle" for product "Mysql" and version "5.0.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.8
Search vendor "Oracle" for product "Mysql" and version "5.0.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.9
Search vendor "Oracle" for product "Mysql" and version "5.0.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.11
Search vendor "Oracle" for product "Mysql" and version "5.0.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.12
Search vendor "Oracle" for product "Mysql" and version "5.0.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.13
Search vendor "Oracle" for product "Mysql" and version "5.0.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.14
Search vendor "Oracle" for product "Mysql" and version "5.0.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.18
Search vendor "Oracle" for product "Mysql" and version "5.0.18"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.19
Search vendor "Oracle" for product "Mysql" and version "5.0.19"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.21
Search vendor "Oracle" for product "Mysql" and version "5.0.21"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.22
Search vendor "Oracle" for product "Mysql" and version "5.0.22"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.23
Search vendor "Oracle" for product "Mysql" and version "5.0.23"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.27
Search vendor "Oracle" for product "Mysql" and version "5.0.27"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.33
Search vendor "Oracle" for product "Mysql" and version "5.0.33"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.37
Search vendor "Oracle" for product "Mysql" and version "5.0.37"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.41
Search vendor "Oracle" for product "Mysql" and version "5.0.41"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.45
Search vendor "Oracle" for product "Mysql" and version "5.0.45"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.51
Search vendor "Oracle" for product "Mysql" and version "5.0.51"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.67
Search vendor "Oracle" for product "Mysql" and version "5.0.67"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.75
Search vendor "Oracle" for product "Mysql" and version "5.0.75"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.77
Search vendor "Oracle" for product "Mysql" and version "5.0.77"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.81
Search vendor "Oracle" for product "Mysql" and version "5.0.81"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.83
Search vendor "Oracle" for product "Mysql" and version "5.0.83"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.85
Search vendor "Oracle" for product "Mysql" and version "5.0.85"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.86
Search vendor "Oracle" for product "Mysql" and version "5.0.86"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.88
Search vendor "Oracle" for product "Mysql" and version "5.0.88"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.89
Search vendor "Oracle" for product "Mysql" and version "5.0.89"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.90
Search vendor "Oracle" for product "Mysql" and version "5.0.90"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.91
Search vendor "Oracle" for product "Mysql" and version "5.0.91"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.5
Search vendor "Mysql" for product "Mysql" and version "5.1.5"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.23
Search vendor "Mysql" for product "Mysql" and version "5.1.23"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.31
Search vendor "Mysql" for product "Mysql" and version "5.1.31"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.32
Search vendor "Mysql" for product "Mysql" and version "5.1.32"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.34
Search vendor "Mysql" for product "Mysql" and version "5.1.34"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.37
Search vendor "Mysql" for product "Mysql" and version "5.1.37"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1
Search vendor "Oracle" for product "Mysql" and version "5.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.1
Search vendor "Oracle" for product "Mysql" and version "5.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.2
Search vendor "Oracle" for product "Mysql" and version "5.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.3
Search vendor "Oracle" for product "Mysql" and version "5.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.4
Search vendor "Oracle" for product "Mysql" and version "5.1.4"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.6
Search vendor "Oracle" for product "Mysql" and version "5.1.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.7
Search vendor "Oracle" for product "Mysql" and version "5.1.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.8
Search vendor "Oracle" for product "Mysql" and version "5.1.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.9
Search vendor "Oracle" for product "Mysql" and version "5.1.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.10
Search vendor "Oracle" for product "Mysql" and version "5.1.10"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.11
Search vendor "Oracle" for product "Mysql" and version "5.1.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.12
Search vendor "Oracle" for product "Mysql" and version "5.1.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.13
Search vendor "Oracle" for product "Mysql" and version "5.1.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.14
Search vendor "Oracle" for product "Mysql" and version "5.1.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.15
Search vendor "Oracle" for product "Mysql" and version "5.1.15"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.16
Search vendor "Oracle" for product "Mysql" and version "5.1.16"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.17
Search vendor "Oracle" for product "Mysql" and version "5.1.17"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.30
Search vendor "Oracle" for product "Mysql" and version "5.1.30"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.33
Search vendor "Oracle" for product "Mysql" and version "5.1.33"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.35
Search vendor "Oracle" for product "Mysql" and version "5.1.35"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.36
Search vendor "Oracle" for product "Mysql" and version "5.1.36"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.38
Search vendor "Oracle" for product "Mysql" and version "5.1.38"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.39
Search vendor "Oracle" for product "Mysql" and version "5.1.39"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.40
Search vendor "Oracle" for product "Mysql" and version "5.1.40"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.41
Search vendor "Oracle" for product "Mysql" and version "5.1.41"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.42
Search vendor "Oracle" for product "Mysql" and version "5.1.42"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.43
Search vendor "Oracle" for product "Mysql" and version "5.1.43"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.44
Search vendor "Oracle" for product "Mysql" and version "5.1.44"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.45
Search vendor "Oracle" for product "Mysql" and version "5.1.45"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.46
Search vendor "Oracle" for product "Mysql" and version "5.1.46"
-
Affected