6.4
CVSSv2

CVE-2000-0045

Published: 11/01/2000 Updated: 07/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql 3.22.27

oracle mysql 3.22.29

oracle mysql 3.23.8

Exploits

source: wwwsecurityfocuscom/bid/926/info MySQL is a popular RDBMS used by many websites as a back-end It is possible for users with GRANT access to change passwords for every user in the database (including the mysql superuser) MySQL also ships with a default "test" account which has GRANT privileges and is unpassworded, meaning anyone ...