CVE-2001-1275
published 2001-01-19CVE-2001-1275: MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table…
PriorityP419high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.53%
41.4th percentile
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | mysql | <= 3.23.31 | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jr9h-ffpv-wrqm: MySQL before 3
ghsa_unreviewed·2022-04-30
CVE-2001-1275 [HIGH] GHSA-jr9h-ffpv-wrqm: MySQL before 3
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
Red Hat
security flaw
vendor_redhat·2001-01-23·CVSS 7.2
CVE-2001-1275 [HIGH] security flaw
security flaw
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=98089552030459&w=2http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txthttp://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3http://www.redhat.com/support/errata/RHSA-2001-003.htmlhttp://marc.info/?l=bugtraq&m=98089552030459&w=2http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txthttp://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3http://www.redhat.com/support/errata/RHSA-2001-003.html
2001-01-19
Published