First published: Tue Oct 02 2001(Updated: )
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | =1.1 | |
Oracle MySQL | =3.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2001-1255 is considered high due to the risk of unauthorized access to the MySQL database.
To fix CVE-2001-1255, change the MySQL password storage method to secure hashing instead of storing it in plain text in the my.ini file.
CVE-2001-1255 affects users of WinMySQLadmin version 1.1 and MySQL version 3.23.
The potential impacts of CVE-2001-1255 include unauthorized access to sensitive database information and possible data breaches.
CVE-2001-1255 is a local vulnerability, requiring an attacker to have local access to the system hosting the MySQL database.