LOW · 3.6

CVE-2006-4226

MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs o...

Vulnerability Description

MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.

CVSS Score

3.6

LOW

AV:N/AC:H/Au:S/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MysqlMysql4.1.0
OracleMysql4.0.0

References

FAQ

What is CVE-2006-4226?

CVE-2006-4226 is a vulnerability with a CVSS score of 3.6 (LOW). MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs o...

How severe is CVE-2006-4226?

CVE-2006-4226 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-4226?

Check the references section above for vendor advisories and patch information. Affected products include: Mysql Mysql, Oracle Mysql.