« List of all CVEs

CVE-2005-2573

Published: 8/16/2005 Last updated: 8/7/2024 Reserved: 8/16/2005

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-mysql

Products affected (1)

Product Vendor Version
n/a n/a < bb71e040323175e18c233a9afef32ba14fa64eb7

References (12)