cbcvebase.
CVE-2001-1275
published 2001-01-19

CVE-2001-1275: MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table…

PriorityP419high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.53%
41.4th percentile
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.

Affected

1 ranges
VendorProductVersion rangeFixed in
oraclemysql<= 3.23.31

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.