MySQL < 5.0.51 RENAME TABLE Symlink System Table Overwrite
low Log Correlation Engine Plugin ID 801146
Synopsis
The remote database server is susceptible to a local symlink attack.
Description
The version of MySQL installed on the remote host reportedly fails to check whether a file to which a symlink points exists when using RENAME TABLE against a table with explicit DATA DIRECTORY and INDEX DIRECTORY options. A local attacker may be able to leverage this issue to overwrite system table information by replacing the file to which the symlink points.