CVE: CVE-2002-1374

Export to Word

The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.

Threat-Mapped Scoring

Score: 3.25

Priority: P2 - Serious (High)

EPSS

Score: 0.25364
Percentile: 0.95956

CVSS Scoring

CVSS v2 Score: 7.5

Severity:

Affected Products

← Back to Home