MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation30 reference(s) from NVD