← All CVEs

CVE-2002-1374

high · 7.5

The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.

7.5
CVSS
20.5%
EPSS (exploit prob.)
97th
EPSS percentile
2002-12-23
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
oraclemysql3.22.26
oraclemysql3.22.27
oraclemysql3.22.28
oraclemysql3.22.29
oraclemysql3.22.30
oraclemysql3.22.32
oraclemysql3.23.2
oraclemysql3.23.3
oraclemysql3.23.4
oraclemysql3.23.5
oraclemysql3.23.8
oraclemysql3.23.9
oraclemysql3.23.10
oraclemysql3.23.23
oraclemysql3.23.24
oraclemysql3.23.25
oraclemysql3.23.26
oraclemysql3.23.27
oraclemysql3.23.28
oraclemysql3.23.29
oraclemysql3.23.30
oraclemysql3.23.31
oraclemysql3.23.34
oraclemysql3.23.36
oraclemysql3.23.37
oraclemysql3.23.38
oraclemysql3.23.39
oraclemysql3.23.40
oraclemysql3.23.41
oraclemysql3.23.42
oraclemysql3.23.43
oraclemysql3.23.44
oraclemysql3.23.45
oraclemysql3.23.46
oraclemysql3.23.47
oraclemysql3.23.48
oraclemysql3.23.49
oraclemysql3.23.50
oraclemysql3.23.51
oraclemysql3.23.52

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1374