Back to search
CVE-2009-3102
Published: Sep 8, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The doHotCopy subroutine in socket-server.pl in Zmanda Recovery Manager (ZRM) for MySQL 2.x before 2.1.1 allows remote attackers to execute arbitrary commands via vectors involving a crafted $MYSQL_BINPATH variable.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://twitter.com/elegerov/statuses/3518763099
x_refsource_MISC
http://twitter.com/elegerov/statuses/3547652507
x_refsource_MISC
zrm-socketserver-command-execution(52977)
vdb-entry
x_refsource_XF
zrm-mysqlhotcopy-priv-escalation(52978)
vdb-entry
x_refsource_XF
http://forums.zmanda.com/showthread.php?p=8068
x_refsource_MISC
36424
third-party-advisory
x_refsource_SECUNIA
36429
third-party-advisory
x_refsource_SECUNIA
http://www.intevydis.com/blog/?p=51
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now