CVE-2016-6662 is an external-control-of-configuration vulnerability in Oracle MySQL, MariaDB, and Percona Server. A sufficiently privileged database user can abuse general logging by directing the general_log_file setting to a database-server configuration location and writing attacker-controlled configuration directives. An injected malloc_lib directive is processed by the root-executed mysqld_safe startup wrapper, causing it to preload an attacker-controlled shared library before the database daemon drops privileges. Affected releases include MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier; MariaDB before 5.5.51, 10.0.27, and 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.32-78.0, and 5.7.14-7. Vendor version-status reporting for certain MySQL fixed releases was disputed at the time of disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a penetration testing lab for CVE-2016-6662, a MySQL Remote Root Code Execution vulnerability. The structure includes Dockerfiles for both the web (PHP/Apache) and database (MySQL 5.6) services, a SQL dump to initialize the database, and a web application with a vulnerable endpoint (src/ajax.php). The exploit involves using SQL injection to extract a flag from the database and to write a PHP web shell to the web root using MySQL's 'SELECT ... INTO OUTFILE' capability. The web shell allows arbitrary command execution, enabling the attacker to read the flag from /flag.txt. The repository provides a realistic environment for demonstrating and practicing exploitation of this MySQL vulnerability, including all necessary configuration files and a sample vulnerable application. The main attack vector is network-based, targeting the web application's API endpoint. The exploit is a proof-of-concept, as it demonstrates the vulnerability and provides a working payload (web shell), but does not include advanced automation or weaponization.
This repository contains a working exploit for CVE-2016-6662, a critical vulnerability in MySQL that allows remote attackers to achieve root code execution via SQL injection. The main exploit script ('From SQL injection to root shell.py') is a Python program that crafts a series of SQL injection payloads to write a malicious trigger and a custom shared library ('mysql_hookandroot_lib.so', compiled from 'mysql_hookandroot_lib.c') into the MySQL data directory. The exploit targets a web application endpoint (http://192.168.77.101/labs/pokemon_pdo.php) vulnerable to SQL injection, and leverages MySQL's ability to write files and load custom libraries via configuration injection. The C shared library, when loaded by mysqld_safe, hooks execvp() to spawn a reverse root shell as root to the attacker's machine (192.168.77.1:7777), and then cleans up the injected configuration to avoid detection. The repository includes a README and a project configuration file, but the core exploit logic is in the Python and C files. This exploit is operational and demonstrates a full chain from SQL injection to root shell on a vulnerable MySQL installation.
This repository contains a proof-of-concept exploit for CVE-2016-6662, a critical remote root code execution vulnerability in MySQL (<=5.7.14, 5.6.32, 5.5.51) and related clones (MariaDB, PerconaDB). The exploit is implemented in Python (rce_mysql.py) and requires valid MySQL credentials with sufficient privileges and a writable my.cnf file. The exploit works by uploading a malicious shared library (mysql_hookandroot_lib.so) to the MySQL data directory, creating a trigger to inject a preload directive into the MySQL configuration, and then waiting for the MySQL service to restart, at which point the library is loaded and executed as root. The exploit sets up a netcat listener on TCP port 6033 to receive a root shell. The repository also includes a detailed advisory (description.txt) explaining the vulnerability, affected versions, and exploitation steps. The exploit is a POC and not fully weaponized, as it only works when the attacker can append to an existing writable my.cnf file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific vulnerability referenced as an example of exploiting Internet-facing applications for initial access; the content does not provide technical details beyond the CVE reference.
MySQL general-log configuration-file write flaw that could allow an administrative or FILE-privileged database user to achieve root command execution.
A MariaDB/MySQL general-log configuration-file write flaw that can allow a privileged database user to execute arbitrary commands as root.
A MySQL logging-functionality flaw that permits users with administrative or FILE privileges to write MySQL configuration files and potentially execute arbitrary commands as root.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.