First published: Sun Jul 15 2007(Updated: )
MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | =5.0.41 | |
MySQL | =5.0.44 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3781 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information without proper privileges.
To fix CVE-2007-3781, update MySQL Community Server to version 5.0.45 or later where this vulnerability is addressed.
CVE-2007-3781 affects MySQL Community Server versions 5.0.41 and 5.0.44.
CVE-2007-3781 can expose sensitive information such as the structure of the source table during a CREATE TABLE LIKE operation.
Yes, CVE-2007-3781 can be exploited by remote authenticated users to gain unauthorized access to table structure information.