Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 before 5.1.46 does not check privileges before uninstalling a plugin, which allows remote attackers to uninstall arbitrary plugins via the UNINSTALL PLUGIN command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MySQL 'mysql_uninstall_plugin'函数权限许可和访问控制漏洞
Vulnerability Description
Oracle MySQL是美国甲骨文(Oracle)公司的一套开源的关系数据库管理系统。该数据库系统具有性能高、成本低、可靠性好等特点。 MySQL的sql/sql_plugin.cc的mysql_uninstall_plugin函数存在权限许可和访问控制漏洞,在卸载插件时,不验证用户权限,远程攻击者可以通过UNINSTALL PLUGIN命令卸载任意插件。
CVSS Information
N/A
Vulnerability Type
N/A