Record summary

CVE-2019-25475 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.

Description

SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

SQL Server Password Changer Denial of Service Exploit

Browse Top-Password / SQL Server Password Changer Denial of Service Exploit
CVE List1.90affected

Proofs of concept

1

Catalogued exploits

ExploitDBSQL Server Password Changer 1.90 - Denial of ServiceExploitDB exploitby Velayutham Selvaraj_ Praveen ThiyagarayamNot analyzed1 file
ExploitDB

PoC details

References

3