MySQL SHOW GRANTS Pasword Hash Disclosure Vulnerability

An attacker using the SHOW grants query can obtain encrypted users' passwords.

Using a dictionary attack, an attacker can read these password hashes, and further compromise users' accounts.


 

Privacy Statement
Copyright 2010, SecurityFocus