Skip to main content

CVE-2007-2691

Severity Medium
Score 4.9/10

Summary

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

  • MEDIUM
  • NETWORK
  • SINGLE
  • PARTIAL
  • NONE
  • PARTIAL

References

Advisory Timeline

  • Published