CVE-2002-1374

MySQL <3.23.54, <4.0.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Andi · cremoteunix
https://www.exploit-db.com/exploits/22084

Scores

EPSS 0.2536
EPSS Percentile 96.2%

Details

Status published
Products (50)
oracle/mysql 3.22.26
oracle/mysql 3.22.27
oracle/mysql 3.22.28
oracle/mysql 3.22.29
oracle/mysql 3.22.30
oracle/mysql 3.22.32
oracle/mysql 3.23.2
oracle/mysql 3.23.3
oracle/mysql 3.23.4
oracle/mysql 3.23.5
... and 40 more
Published Dec 23, 2002
Tracked Since Feb 18, 2026