MEDIUM · 4.0

CVE-2007-3781

MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive infor...

Vulnerability Description

MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MysqlCommunity Server5.0.41

References

FAQ

What is CVE-2007-3781?

CVE-2007-3781 is a vulnerability with a CVSS score of 4.0 (MEDIUM). MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive infor...

How severe is CVE-2007-3781?

CVE-2007-3781 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3781?

Check the references section above for vendor advisories and patch information. Affected products include: Mysql Community Server.