WinMySQLadmin Plain Text Password Storage Vulnerability
BID:3381
Info
WinMySQLadmin Plain Text Password Storage Vulnerability
| Bugtraq ID: | 3381 |
| Class: | Design Error |
| CVE: |
CVE-2001-1255 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 02 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered and posted to Bugtraq by Cabezon Aurélien <[email protected]> on Oct 2, 2001. |
| Vulnerable: |
MySQL AB WinMySQLadmin 1.1 MySQL AB MySQL 3.23 .x |
| Not Vulnerable: | |
Discussion
WinMySQLadmin Plain Text Password Storage Vulnerability
A vunerability exists in WinMySQLadmin 1.1 that may result in the disclosure of sensitive authentication information for MySQL.
If a local user gained access to the 'my.ini' file, it is possible to retrieve configuration and authentication information for MySQL. The contents of this file are in plain text.
A vunerability exists in WinMySQLadmin 1.1 that may result in the disclosure of sensitive authentication information for MySQL.
If a local user gained access to the 'my.ini' file, it is possible to retrieve configuration and authentication information for MySQL. The contents of this file are in plain text.
Exploit / POC
WinMySQLadmin Plain Text Password Storage Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WinMySQLadmin Plain Text Password Storage Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WinMySQLadmin Plain Text Password Storage Vulnerability
References:
References: