MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2007-05-16 01:19
Updated : 2024-02-04 17:13
NVD link : CVE-2007-2691
Mitre link : CVE-2007-2691
CVE.ORG link : CVE-2007-2691
JSON object : View
Products Affected
mysql
- mysql
debian
- debian_linux
canonical
- ubuntu_linux
CWE