mirror of
https://github.com/MariaDB/server.git
synced 2025-08-26 01:44:06 +03:00
"load data infile .." allowed for access to unautohorized tables. Due to a faulty if-statement it was possible to circumvent the secure_file_priv restriction.
7 lines
346 B
Plaintext
7 lines
346 B
Plaintext
CREATE TABLE t1 (c1 INT);
|
|
LOAD DATA INFILE "t1.MYI" into table t1;
|
|
ERROR HY000: The MySQL server is running with the --secure-file-priv option so it cannot execute this statement
|
|
LOAD DATA INFILE "/test" into table t1;
|
|
ERROR HY000: The MySQL server is running with the --secure-file-priv option so it cannot execute this statement
|
|
DROP TABLE t1;
|