Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2005-2573

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash () character.

  • Published: Aug 16, 2005
  • Updated: Apr 13, 2023
  • CVE: CVE-2005-2573
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

No CWE or OWASP classifications available.

Software From Fixed in
mysql / mysql 5.0.3 5.0.3.x
mysql / mysql 4.1.10 4.1.10.x
mysql / mysql 5.0.2 5.0.2.x
mysql / mysql 5.0.1 5.0.1.x
mysql / mysql 4.1.0 4.1.0.x
mysql / mysql 5.0.4 5.0.4.x
mysql / mysql 4.1.3 4.1.3.x
oracle / mysql 4.0.0 4.0.0.x
oracle / mysql 4.0.1 4.0.1.x
oracle / mysql 4.0.2 4.0.2.x
oracle / mysql 4.0.3 4.0.3.x
oracle / mysql 4.0.4 4.0.4.x
oracle / mysql 4.0.5 4.0.5.x
oracle / mysql 4.0.5a 4.0.5a.x
oracle / mysql 4.0.6 4.0.6.x
oracle / mysql 4.0.7 4.0.7.x
oracle / mysql 4.0.7-gamma 4.0.7-gamma.x
oracle / mysql 4.0.8-gamma 4.0.8-gamma.x
oracle / mysql 4.0.8 4.0.8.x
oracle / mysql 4.0.9 4.0.9.x
oracle / mysql 4.0.9-gamma 4.0.9-gamma.x
oracle / mysql 4.0.10 4.0.10.x
oracle / mysql 4.0.11-gamma 4.0.11-gamma.x
oracle / mysql 4.0.11 4.0.11.x
oracle / mysql 4.0.12 4.0.12.x
oracle / mysql 4.0.13 4.0.13.x
oracle / mysql 4.0.14 4.0.14.x
oracle / mysql 4.0.15 4.0.15.x
oracle / mysql 4.0.18 4.0.18.x
oracle / mysql 4.0.20 4.0.20.x
oracle / mysql 4.0.21 4.0.21.x
oracle / mysql 4.0.24 4.0.24.x
oracle / mysql 4.1.0-alpha 4.1.0-alpha.x
oracle / mysql 4.1.2-alpha 4.1.2-alpha.x
oracle / mysql 4.1.3-beta 4.1.3-beta.x
oracle / mysql 4.1.4 4.1.4.x
oracle / mysql 4.1.5 4.1.5.x
oracle / mysql 5.0.0-alpha 5.0.0-alpha.x