Vulnerability Name: | CVE-2006-0369 | ||||||||
Assigned: | 2006-01-22 | ||||||||
Published: | 2006-01-22 | ||||||||
Updated: | 2019-12-17 | ||||||||
Summary: | ** DISPUTED ** MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. Note: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0369 Source: BUGTRAQ Type: UNKNOWN 20060120 MySQL 5.0 information leak? Source: BUGTRAQ Type: UNKNOWN 20060121 RE: MySQL 5.0 information leak? Source: BUGTRAQ Type: UNKNOWN 20060121 Re: MySQL 5.0 information leak? Source: BUGTRAQ Type: UNKNOWN 20060122 Re: MySQL 5.0 information leak? Source: BUGTRAQ Type: UNKNOWN 20060124 Re: MySQL 5.0 information leak? Source: BUGTRAQ Type: UNKNOWN 20060123 RE: MySQL 5.0 information leak? Source: BUGTRAQ Type: UNKNOWN 20060128 Re: MySQL 5.0 information leak? | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |