AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-2008

LOW · CVSS 3.5 EPSS 9.01%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-07-13 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 3.5. It may be remotely exploitable. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.

CVE
CVE-2010-2008
Severity
LOW
CVSS
3.5
EPSS
9.01%

Original NVD Description

MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.