Vulnerability Details CVE-2005-0684
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.74
EPSS Ranking 98.7%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2005-0684
-
cpe:2.3:a:mysql:maxdb:7.5.00
-
cpe:2.3:a:mysql:maxdb:7.5.00.08
-
cpe:2.3:a:mysql:maxdb:7.5.00.11
-
cpe:2.3:a:mysql:maxdb:7.5.00.12
-
cpe:2.3:a:mysql:maxdb:7.5.00.14
-
cpe:2.3:a:mysql:maxdb:7.5.00.15
-
cpe:2.3:a:mysql:maxdb:7.5.00.16
-
cpe:2.3:a:mysql:maxdb:7.5.00.18
-
cpe:2.3:a:mysql:maxdb:7.5.00.19
-
cpe:2.3:a:mysql:maxdb:7.5.00.23