3 ms·
i agree with that .. this isn't remote at all.
by bechampion 10y ago
i agree with that .. this isn't remote at all.
- bechampion 10y agomaybe a sql injection ....and escalate from there..
- TickleSteve 10y agoThe point is that it is exploitable from SQL, therefore is also exploitable from the application that is creating the database. This would be a target for a sql injection exploit and so is remotely exploitable
- whyleyc 10y agoThat requires your application to be vulnerable to two types of exploit in order to pull off RCE - if you are vulnerable to SQLi there are likely a whole raft of other issues which would give you a remote shell. As a standalone issue I agree with the GP comment - this bug is not a RCE issue, it's privilege escalation.
- deleted 10y ago[deleted]
- bechampion 10y agoI'm sorry I disagree , you're assuming that the "application" is vulnerable to sql injection and others.
- 0x0 10y agoNot everyone limits mysql to just localhost. Some setups serve mysql over tcp/ip, sometimes even on the internet. Maybe you wouldn't trust mysql's ssl usage or username/password auth mechanisms, but they are there, and some people use those features. So this should certainly be considered a remote vulnerability, as long as the exploit can be launched from the client side of a mysql connection.