Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2007-6303

MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.

  • Published: Dec 10, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-6303
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
mysql / mysql 5.0.5 5.0.5.x
mysql / mysql 5.0.10 5.0.10.x
mysql / mysql 5.0.0 5.0.0.x
mysql / mysql 5.0.15 5.0.15.x
mysql / mysql 5.0.17 5.0.17.x
mysql / mysql 5.0.5.0.21 5.0.5.0.21.x
mysql / mysql 5.0.3 5.0.3.x
mysql / mysql 5.0.24 5.0.24.x
mysql / mysql 5.0.2 5.0.2.x
mysql / mysql 5.0.22.1.0.1 5.0.22.1.0.1.x
mysql / mysql 5.0.20 5.0.20.x
mysql / mysql 5.0.1 5.0.1.x
mysql / mysql 5.0.4 5.0.4.x
mysql / mysql 5.0.16 5.0.16.x
oracle / mysql 6.0.0 6.0.0.x
oracle / mysql 6.0.1 6.0.1.x
oracle / mysql 6.0.2 6.0.2.x
oracle / mysql 6.0.3 6.0.3.x
oracle / mysql 5.0.41 5.0.41.x
oracle / mysql 5.1.1 5.1.1.x
oracle / mysql 5.1.2 5.1.2.x
oracle / mysql 5.1.10 5.1.10.x
oracle / mysql 5.1.11 5.1.11.x
oracle / mysql 5.1.12 5.1.12.x
oracle / mysql 5.1.13 5.1.13.x
oracle / mysql 5.1.14 5.1.14.x
oracle / mysql 5.1.15 5.1.15.x
oracle / mysql 5.1.16 5.1.16.x
oracle / mysql 5.1.17 5.1.17.x