Description
** DISPUTED ** MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access.
Remediation
References
Related Vulnerabilities
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29203)
WordPress Plugin GlotPress Information Disclosure (2.2.1)
Apache HTTP Server Interpretation Conflict Vulnerability (CVE-2022-37436)
MySQL CVE-2022-21638 Vulnerability (CVE-2022-21638)
WordPress Plugin Paid Business Listings Blind SQL Injection (1.0.2)