论坛: 菜鸟乐园 标题: 扫描自己的机器发现以下漏洞! 复制本贴地址    
作者: laoqiang [laoqiang]    论坛用户   登录
漏洞                        mysql (3306/tcp)

You are running a version of MySQL which is
older than version 4.0.15.

If you have not patched this version, then
any attacker who has the credentials to connect to this
server may execute arbitrary code on this host with
the privileges of the mysql database by changing his
password with a too long one containing a shell code.


Solution : Upgrade to MySQL 3.0.58 or 4.0.15
Risk factor : Medium
CVE_ID : CAN-2003-0780
BUGTRAQ_ID : 8590
NESSUS_ID : 11842
Other references : RHSA:RHSA-2003:281-01, SuSE:SUSE-SA:2003:042



地主 发表时间: 04-08-09 13:48

论坛: 菜鸟乐园

20CN网络安全小组版权所有
Copyright © 2000-2010 20CN Security Group. All Rights Reserved.
论坛程序编写:NetDemon

粤ICP备05087286号