Description
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
Exploits (1)
References (16)
Scores
EPSS
0.2536
EPSS Percentile
96.2%
Details
Status
published
Products (50)
oracle/mysql
3.22.26
oracle/mysql
3.22.27
oracle/mysql
3.22.28
oracle/mysql
3.22.29
oracle/mysql
3.22.30
oracle/mysql
3.22.32
oracle/mysql
3.23.2
oracle/mysql
3.23.3
oracle/mysql
3.23.4
oracle/mysql
3.23.5
... and 40 more
Published
Dec 23, 2002
Tracked Since
Feb 18, 2026