MySQL Enterprise Server 5.0 < 5.0.60 MyISAM Table Privilege Check Bypass
low Log Correlation Engine Plugin ID 801131
New! Plugin Severity Now Using CVSS v3
The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
The remote database server allows a local user to circumvent privileges.
The version of MySQL Enterprise Server installed on the remote host reportedly allows a local user to circumvent privileges through creation of MyISAM tables using the 'DATA DIRECTORY' and 'INDEX DIRECTORY' options to overwrite existing table files in the application's data directory.