Vulnerability Details CVE-2001-0407
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.3%
CVSS Severity
CVSS v2 Score 4.6
Products affected by CVE-2001-0407
-
-
cpe:2.3:a:oracle:mysql:1.5.1
-
cpe:2.3:a:oracle:mysql:3.20
-
cpe:2.3:a:oracle:mysql:3.20.32a
-
cpe:2.3:a:oracle:mysql:3.21
-
cpe:2.3:a:oracle:mysql:3.22
-
cpe:2.3:a:oracle:mysql:3.22.26
-
cpe:2.3:a:oracle:mysql:3.22.27
-
cpe:2.3:a:oracle:mysql:3.22.28
-
cpe:2.3:a:oracle:mysql:3.22.29
-
cpe:2.3:a:oracle:mysql:3.22.30
-
cpe:2.3:a:oracle:mysql:3.22.32
-
cpe:2.3:a:oracle:mysql:3.23
-
cpe:2.3:a:oracle:mysql:3.23.0
-
cpe:2.3:a:oracle:mysql:3.23.1
-
cpe:2.3:a:oracle:mysql:3.23.10
-
cpe:2.3:a:oracle:mysql:3.23.11
-
cpe:2.3:a:oracle:mysql:3.23.12
-
cpe:2.3:a:oracle:mysql:3.23.13
-
cpe:2.3:a:oracle:mysql:3.23.14
-
cpe:2.3:a:oracle:mysql:3.23.15
-
cpe:2.3:a:oracle:mysql:3.23.16
-
cpe:2.3:a:oracle:mysql:3.23.17
-
cpe:2.3:a:oracle:mysql:3.23.18
-
cpe:2.3:a:oracle:mysql:3.23.19
-
cpe:2.3:a:oracle:mysql:3.23.2
-
cpe:2.3:a:oracle:mysql:3.23.20
-
cpe:2.3:a:oracle:mysql:3.23.21
-
cpe:2.3:a:oracle:mysql:3.23.22
-
cpe:2.3:a:oracle:mysql:3.23.23
-
cpe:2.3:a:oracle:mysql:3.23.24
-
cpe:2.3:a:oracle:mysql:3.23.25
-
cpe:2.3:a:oracle:mysql:3.23.26
-
cpe:2.3:a:oracle:mysql:3.23.27
-
cpe:2.3:a:oracle:mysql:3.23.28
-
cpe:2.3:a:oracle:mysql:3.23.29
-
cpe:2.3:a:oracle:mysql:3.23.3
-
cpe:2.3:a:oracle:mysql:3.23.30
-
cpe:2.3:a:oracle:mysql:3.23.31
-
cpe:2.3:a:oracle:mysql:3.23.32
-
cpe:2.3:a:oracle:mysql:3.23.33
-
cpe:2.3:a:oracle:mysql:3.23.34
-
cpe:2.3:a:oracle:mysql:3.23.35
-
cpe:2.3:a:oracle:mysql:3.23.36
-
cpe:2.3:a:oracle:mysql:3.23.4
-
cpe:2.3:a:oracle:mysql:3.23.5
-
cpe:2.3:a:oracle:mysql:3.23.6
-
cpe:2.3:a:oracle:mysql:3.23.7
-
cpe:2.3:a:oracle:mysql:3.23.8
-
cpe:2.3:a:oracle:mysql:3.23.9