Description
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
Affected products
- oracle / mysql3.23.36
Exploits & proofs of concept
- exploit-dbMySQL 3.20.32 a/3.23.34 - Root Operation Symbolic Link File Overwritingby lesha
Updated 18m ago · 8 sources