VulnerabilityModified
CVE-2007-6313
MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
MEDIUM 6.5EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mysql/mysql community server
- Source
- cve@mitre.org
References
- http://bugs.mysql.com/31611
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html
- http://osvdb.org/43179
- http://www.securitytracker.com/id?1019083
- http://www.vupen.com/english/advisories/2008/0560/references
- http://bugs.mysql.com/31611
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html
- http://osvdb.org/43179
- http://www.securitytracker.com/id?1019083
- http://www.vupen.com/english/advisories/2008/0560/references
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.