Vulnerabilities > Oracle > Mysql > 4.0.23

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0709 Code Injection vulnerability in multiple products
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
local
low complexity
mysql oracle CWE-94
4.6