Vulnerability Details CVE-2002-1921
The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.3%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2002-1921
-
cpe:2.3:a:oracle:mysql:3.20.32a
-
cpe:2.3:a:oracle:mysql:3.22.26
-
cpe:2.3:a:oracle:mysql:3.22.27
-
cpe:2.3:a:oracle:mysql:3.22.28
-
cpe:2.3:a:oracle:mysql:3.22.29
-
cpe:2.3:a:oracle:mysql:3.22.30
-
cpe:2.3:a:oracle:mysql:3.22.32
-
cpe:2.3:a:oracle:mysql:3.23.10
-
cpe:2.3:a:oracle:mysql:3.23.2
-
cpe:2.3:a:oracle:mysql:3.23.23
-
cpe:2.3:a:oracle:mysql:3.23.24
-
cpe:2.3:a:oracle:mysql:3.23.25
-
cpe:2.3:a:oracle:mysql:3.23.26
-
cpe:2.3:a:oracle:mysql:3.23.27
-
cpe:2.3:a:oracle:mysql:3.23.28
-
cpe:2.3:a:oracle:mysql:3.23.29
-
cpe:2.3:a:oracle:mysql:3.23.3
-
cpe:2.3:a:oracle:mysql:3.23.30
-
cpe:2.3:a:oracle:mysql:3.23.31
-
cpe:2.3:a:oracle:mysql:3.23.34
-
cpe:2.3:a:oracle:mysql:3.23.36
-
cpe:2.3:a:oracle:mysql:3.23.37
-
cpe:2.3:a:oracle:mysql:3.23.38
-
cpe:2.3:a:oracle:mysql:3.23.39
-
cpe:2.3:a:oracle:mysql:3.23.4
-
cpe:2.3:a:oracle:mysql:3.23.40
-
cpe:2.3:a:oracle:mysql:3.23.41
-
cpe:2.3:a:oracle:mysql:3.23.42
-
cpe:2.3:a:oracle:mysql:3.23.43
-
cpe:2.3:a:oracle:mysql:3.23.44
-
cpe:2.3:a:oracle:mysql:3.23.45
-
cpe:2.3:a:oracle:mysql:3.23.46
-
cpe:2.3:a:oracle:mysql:3.23.47
-
cpe:2.3:a:oracle:mysql:3.23.48
-
cpe:2.3:a:oracle:mysql:3.23.49
-
cpe:2.3:a:oracle:mysql:3.23.5
-
cpe:2.3:a:oracle:mysql:3.23.50
-
cpe:2.3:a:oracle:mysql:3.23.51
-
cpe:2.3:a:oracle:mysql:3.23.52
-
cpe:2.3:a:oracle:mysql:3.23.8
-
cpe:2.3:a:oracle:mysql:3.23.9