TROYANOSYVIRUS
Voltar para CVEs

CVE-2005-2573

N/A

Descricao

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.

This product uses data from the NVD API but is not endorsed or certified by the NVD.