CVE-2001-1274

MySQL <3.23.31 - DoS/Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-1274. PoCs published by Luis Miguel Silva.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in MySQL versions up to 3.23.30 by supplying an excessively long string in a SELECT statement. It overwrites the return address on the stack to execute arbitrary shellcode, granting the attacker a shell with the privileges of the MySQL server.

Description

Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luis Miguel Silva · clocallinux
https://www.exploit-db.com/exploits/20581

This exploit targets a buffer overflow vulnerability in MySQL versions up to 3.23.30 by supplying an excessively long string in a SELECT statement. It overwrites the return address on the stack to execute arbitrary shellcode, granting the attacker a shell with the privileges of the MySQL server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MySQL < 3.23.31
Auth required
Prerequisites: Valid MySQL credentials · Local access to the MySQL client
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000375
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2001/dsa-013
Various Sources vendor-advisory x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-003.html
Mailing List vendor-advisory x_refsource_freebsd
http://marc.info/?l=bugtraq&m=98089552030459&w=2
Vendor Advisory vendor-advisory x_refsource_caldera
http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txt

Scores

EPSS 0.0543
EPSS Percentile 91.7%

Details

Status published
Products (1)
oracle/mysql < 3.23.31
Published Jan 23, 2001
Tracked Since Feb 18, 2026