CVE-2012-5613
MySQL <5.5.19 & MariaDB <5.5.28a - Privilege Escalation
Title source: llmDescription
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
Exploits (7)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/35777
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/23179
metasploit
WORKING POC
EXCELLENT
by sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mysql/mysql_start_up.rb
metasploit
WORKING POC
EXCELLENT
by kingcope, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mysql/mysql_mof.rb
exploitdb
WORKING POC
VERIFIED
by kingcope · perllocallinux
https://www.exploit-db.com/exploits/23077
References (6)
Scores
EPSS
0.8875
EPSS Percentile
99.5%
Classification
CWE
CWE-16
Status
draft
Affected Products (2)
mariadb/mariadb
oracle/mysql
Timeline
Published
Dec 03, 2012
Tracked Since
Feb 18, 2026