Vulnerabilities > CVE-2000-0148 - Unspecified vulnerability in Oracle Mysql

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
oracle
nessus

Summary

MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.

Nessus

NASL familyDatabases
NASL idMYSQL_BAD_PASSWORD.NASL
descriptionThe remote version of MySQL is older than (or as old as) version 3.22.30 or 3.23.10. Thus, it may allow attacker who knows a valid username to access database tables without a valid password.
last seen2020-06-01
modified2020-06-02
plugin id10343
published2000-03-08
reporterThis script is Copyright (C) 2000-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/10343
titleMySQL Short Check String Authentication Bypass