VYPR
Unrated severityNVD Advisory· Published May 17, 2005· Updated Jun 16, 2026

CVE-2005-1636

CVE-2005-1636

Description

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

23
  • MySQL/MySQL5 versions
    cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:mysql:5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*
    • (no CPE)range: >=4.1.0, <4.1.12 ∪ >=5.0.0, <=5.0.4
  • cpe:2.3:a:oracle:mysql:4.0.0:*:*:*:*:*:*:*+ 17 more
    • cpe:2.3:a:oracle:mysql:4.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.11:gamma:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.5a:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.7:gamma:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.8:gamma:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:4.0.9:gamma:*:*:*:*:*:*
    • cpe:2.3:a:oracle:mysql:5.0.0:alpha:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.