CVE-2010-1848
mysql: multiple insufficient table name checks
Severity Score
6.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
Vulnerabilidad de salto de directorio en MySQL v5.0 hasta v5.0.91 y v5.1 anteriores a v5.1.47 permite a usuarios autenticados remotamente saltarse tablas establecidas permitiendo leer definiciones de campos de tablas de su elección, y sobre v5.1 leer o eliminar contenido de tablas de su elección, a través de .. (punto punto) en un nombre de tabla.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-05-06 CVE Reserved
- 2010-05-26 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://bugs.mysql.com/bug.php?id=53371 | X_refsource_confirm | |
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html | X_refsource_confirm | |
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html | X_refsource_confirm | |
http://lists.mysql.com/commits/107532 | X_refsource_misc | |
http://securitytracker.com/id?1024031 | Vdb Entry | |
http://support.apple.com/kb/HT4435 | X_refsource_confirm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10258 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7210 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.0 Search vendor "Mysql" for product "Mysql" and version "5.0.0" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.1 Search vendor "Mysql" for product "Mysql" and version "5.0.1" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.2 Search vendor "Mysql" for product "Mysql" and version "5.0.2" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.3 Search vendor "Mysql" for product "Mysql" and version "5.0.3" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.4 Search vendor "Mysql" for product "Mysql" and version "5.0.4" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.5 Search vendor "Mysql" for product "Mysql" and version "5.0.5" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.5.0.21 Search vendor "Mysql" for product "Mysql" and version "5.0.5.0.21" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.10 Search vendor "Mysql" for product "Mysql" and version "5.0.10" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.15 Search vendor "Mysql" for product "Mysql" and version "5.0.15" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.16 Search vendor "Mysql" for product "Mysql" and version "5.0.16" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.17 Search vendor "Mysql" for product "Mysql" and version "5.0.17" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.20 Search vendor "Mysql" for product "Mysql" and version "5.0.20" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.24 Search vendor "Mysql" for product "Mysql" and version "5.0.24" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.45b Search vendor "Mysql" for product "Mysql" and version "5.0.45b" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.82 Search vendor "Mysql" for product "Mysql" and version "5.0.82" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.84 Search vendor "Mysql" for product "Mysql" and version "5.0.84" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.87 Search vendor "Mysql" for product "Mysql" and version "5.0.87" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.0 Search vendor "Oracle" for product "Mysql" and version "5.0.0" | alpha |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.3 Search vendor "Oracle" for product "Mysql" and version "5.0.3" | beta |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.6 Search vendor "Oracle" for product "Mysql" and version "5.0.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.7 Search vendor "Oracle" for product "Mysql" and version "5.0.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.8 Search vendor "Oracle" for product "Mysql" and version "5.0.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.9 Search vendor "Oracle" for product "Mysql" and version "5.0.9" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.11 Search vendor "Oracle" for product "Mysql" and version "5.0.11" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.12 Search vendor "Oracle" for product "Mysql" and version "5.0.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.13 Search vendor "Oracle" for product "Mysql" and version "5.0.13" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.14 Search vendor "Oracle" for product "Mysql" and version "5.0.14" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.18 Search vendor "Oracle" for product "Mysql" and version "5.0.18" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.19 Search vendor "Oracle" for product "Mysql" and version "5.0.19" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.21 Search vendor "Oracle" for product "Mysql" and version "5.0.21" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.22 Search vendor "Oracle" for product "Mysql" and version "5.0.22" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.23 Search vendor "Oracle" for product "Mysql" and version "5.0.23" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.27 Search vendor "Oracle" for product "Mysql" and version "5.0.27" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.33 Search vendor "Oracle" for product "Mysql" and version "5.0.33" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.37 Search vendor "Oracle" for product "Mysql" and version "5.0.37" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.41 Search vendor "Oracle" for product "Mysql" and version "5.0.41" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.45 Search vendor "Oracle" for product "Mysql" and version "5.0.45" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.51 Search vendor "Oracle" for product "Mysql" and version "5.0.51" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.67 Search vendor "Oracle" for product "Mysql" and version "5.0.67" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.75 Search vendor "Oracle" for product "Mysql" and version "5.0.75" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.77 Search vendor "Oracle" for product "Mysql" and version "5.0.77" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.81 Search vendor "Oracle" for product "Mysql" and version "5.0.81" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.83 Search vendor "Oracle" for product "Mysql" and version "5.0.83" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.85 Search vendor "Oracle" for product "Mysql" and version "5.0.85" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.86 Search vendor "Oracle" for product "Mysql" and version "5.0.86" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.88 Search vendor "Oracle" for product "Mysql" and version "5.0.88" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.89 Search vendor "Oracle" for product "Mysql" and version "5.0.89" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.90 Search vendor "Oracle" for product "Mysql" and version "5.0.90" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.91 Search vendor "Oracle" for product "Mysql" and version "5.0.91" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.1.5 Search vendor "Mysql" for product "Mysql" and version "5.1.5" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.1.23 Search vendor "Mysql" for product "Mysql" and version "5.1.23" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.1.31 Search vendor "Mysql" for product "Mysql" and version "5.1.31" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.1.32 Search vendor "Mysql" for product "Mysql" and version "5.1.32" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.1.34 Search vendor "Mysql" for product "Mysql" and version "5.1.34" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.1.37 Search vendor "Mysql" for product "Mysql" and version "5.1.37" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1 Search vendor "Oracle" for product "Mysql" and version "5.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.1 Search vendor "Oracle" for product "Mysql" and version "5.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.2 Search vendor "Oracle" for product "Mysql" and version "5.1.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.3 Search vendor "Oracle" for product "Mysql" and version "5.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.4 Search vendor "Oracle" for product "Mysql" and version "5.1.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.6 Search vendor "Oracle" for product "Mysql" and version "5.1.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.7 Search vendor "Oracle" for product "Mysql" and version "5.1.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.8 Search vendor "Oracle" for product "Mysql" and version "5.1.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.9 Search vendor "Oracle" for product "Mysql" and version "5.1.9" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.10 Search vendor "Oracle" for product "Mysql" and version "5.1.10" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.11 Search vendor "Oracle" for product "Mysql" and version "5.1.11" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.12 Search vendor "Oracle" for product "Mysql" and version "5.1.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.13 Search vendor "Oracle" for product "Mysql" and version "5.1.13" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.14 Search vendor "Oracle" for product "Mysql" and version "5.1.14" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.15 Search vendor "Oracle" for product "Mysql" and version "5.1.15" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.16 Search vendor "Oracle" for product "Mysql" and version "5.1.16" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.17 Search vendor "Oracle" for product "Mysql" and version "5.1.17" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.30 Search vendor "Oracle" for product "Mysql" and version "5.1.30" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.33 Search vendor "Oracle" for product "Mysql" and version "5.1.33" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.35 Search vendor "Oracle" for product "Mysql" and version "5.1.35" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.36 Search vendor "Oracle" for product "Mysql" and version "5.1.36" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.38 Search vendor "Oracle" for product "Mysql" and version "5.1.38" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.39 Search vendor "Oracle" for product "Mysql" and version "5.1.39" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.40 Search vendor "Oracle" for product "Mysql" and version "5.1.40" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.41 Search vendor "Oracle" for product "Mysql" and version "5.1.41" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.42 Search vendor "Oracle" for product "Mysql" and version "5.1.42" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.43 Search vendor "Oracle" for product "Mysql" and version "5.1.43" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.44 Search vendor "Oracle" for product "Mysql" and version "5.1.44" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.45 Search vendor "Oracle" for product "Mysql" and version "5.1.45" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.46 Search vendor "Oracle" for product "Mysql" and version "5.1.46" | - |
Affected
|