Description
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2815 Vulnerability (CVE-2019-2815)
WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Scripting (4.1.6)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1582)
WordPress Plugin Limit Attempts by BestWebSoft SQL Injection (1.1.0)
WordPress Plugin Testimonial Slider Cross-Site Scripting (1.2.1)