Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6303 (MySQL)

BugsAlert Home > CVE-2007-6303 (MySQL)
 
 

MySQL 5.0.x before 5.0.52, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6303

Learn more about CVE-2007-6303 (MySQL)
 
Tags: cve-2007-6303 mysql

Related Items

      FrSIRT - phpArcadeScript "cat" Parameter Remote SQL Injection Vulnerability

      Cisco Products SNMPv3 Two Vulnerabilities

      Debian update for splitvt

      Infocus: Responding to a Brute Force SSH Attack

      Vuln: Linux Kernel Fib_Semantics.C Out Of Bounds Access Vulnerability

      al Qaeda News Spam: A Malware Diversionary Tactic

      Motorola Surfboard Cable Modem Web Interface Cross-Site Request Forgery

 

Pixel