CVE-2012-5613 describes a privilege escalation vulnerability in MySQL 5.5.19+ and MariaDB 5.5.28a+ when the FILE privilege is improperly assigned to non-administrative users. This allows authenticated attackers to create files as the MySQL administrator, potentially gaining higher privileges. With a CVSS score of 6.0, this issue has a medium severity, requiring authentication and moderate attack complexity, but can lead to partial compromise of confidentiality, integrity, and availability. While not actively exploited in the wild (no KEV entry), exploit modules are available in Metasploit and ExploitDB, indicating a clear path for exploitation. Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.28aCPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:5.5.28a:*:*:*:*:*:*:* | ||
5.5.19CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:5.5.19:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.