CVE-2005-0710

MySQL <4.0.23 & <4.1.11 - Privilege Escalation

Title source: llm

Description

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefano Di Paola · phpremotemultiple
https://www.exploit-db.com/exploits/25210

Scores

EPSS 0.0458
EPSS Percentile 89.3%

Details

Status published
Products (30)
mysql/mysql 4.1.0
mysql/mysql 4.1.3
mysql/mysql 4.1.10
oracle/mysql 3.23.49
oracle/mysql 4.0.0
oracle/mysql 4.0.1
oracle/mysql 4.0.2
oracle/mysql 4.0.3
oracle/mysql 4.0.4
oracle/mysql 4.0.5
... and 20 more
Published May 02, 2005
Tracked Since Feb 18, 2026