peter bassill · operator
$ cve CVE-2010-2008 JSON

CVE-2010-2008 EXPLOIT

3.5
LOW · CVSS 2.0 · EPSS 9% (pctl 95)

Patch early

A public exploit exists.

Description

MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.

Scoring

CVSS3.5 (LOW, v2.0)
VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
EPSS9.01% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploityes
Published2010-07-13
Last modified2026-06-16

Affected (3)

VendorProduct
canonicalubuntu linux
fedoraprojectfedora
oraclemysql

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD