Description
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2039)
Microsoft SQL Server Other Vulnerability (CVE-2000-1086)
WordPress Plugin SVG Support Cross-Site Scripting (2.4.2)
TYPO3 Improper Input Validation Vulnerability (CVE-2009-0258)
Moodle Incorrect Default Permissions Vulnerability (CVE-2012-1157)