First published: Wed Jun 27 2001(Updated: )
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | <=3.23.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2001-0407 is classified as medium, as it allows local users to exploit the directory traversal vulnerability.
CVE-2001-0407 affects MySQL versions before 3.23.36, allowing local users to modify arbitrary files.
To fix CVE-2001-0407, users should upgrade to MySQL version 3.23.36 or later to prevent directory traversal attacks.
CVE-2001-0407 is associated with a directory traversal attack that allows unauthorized file modifications.
No, CVE-2001-0407 can only be exploited by local users with access to the server where MySQL is installed.