CVE-2012-5613

Scores

EPSS

0.888high88.8%
0%20%40%60%80%100%

Percentile: 88.8%

CVSS

4.6medium2.0
0246810

CVSS Score: 4.6/10

All CVSS Scores

CVSS 2.0
4.6

Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P

Description

MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product’s installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvd

CWEs

CWE-16

Exploits

Exploit ID: 23077

Source: exploitdb

URL: https://www.exploit-db.com/exploits/23077

Exploit ID: 23179

Source: exploitdb

URL: https://www.exploit-db.com/exploits/23179

Exploit ID: 35777

Source: exploitdb

URL: https://www.exploit-db.com/exploits/35777

Exploit ID: CVE-2012-5613

Source: github-poc

URL: https://github.com/w4fz5uck5/UDFPwn-CVE-2012-5613

Vulnerable Software (4)

Type: Configuration

Product: mysql-5.1

Operating System: debian

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: mysql-5.5

Operating System: debian

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Vendor: *

Product: mariadb

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:mariadb:mariadb:5.5.28a:*:*:*:*:*:*:*",          "vulnerable": true        },        {          "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: *

Product: mysql

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:mariadb:mariadb:5.5.28a:*:*:*:*:*:*:*",          "vulnerable": true        },        {          "cpe23uri": ...

Source: nvd

End of list