>> MySQL MERGE Table Revoked Privileges Security Bypass and Unauthorized Access Vulnerability
Title : MySQL MERGE Table Revoked Privileges Security Bypass and Unauthorized Access Vulnerability VUPEN ID : VUPEN/ADV-2006-3079 CVE ID : CVE-2006-4031
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-01
Technical Description
A vulnerability has been identified in MySQL, which could be exploited by malicious users to bypass security restrictions. This flaw is due to a design error where access to certain tables is allowed even if the privileges have been revoked, which could be exploited by attackers to gain unauthorized access to a table via a MERGE table.