The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
📦
netbackup_global_data_manager
Vendor: symantec_veritas
Actively Exploited
0
CISA KEV List
PoC / Exploits
2
Code Available
Total RCEs
1
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
14.47%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.5
CVSS
CVE-2002-1374
Exploit Found
Severity: HIGH
7.5
CVSS
CVE-2002-1375
RCE
Exploit Found
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
Severity: HIGH
7.5
CVSS
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Severity: HIGH