CVE-2012-2122
60Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendepss 96%
da publicação à arma0 dias
Publicada no NVD26 de jun.
1ª PoC12 de jun.
metasploit9 de jun.
probabilidade de exploração
96%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
7 exploit(s) público(s)
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 7✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/19092githubgithub.com/Avinza/CVE-2012-2122-scanner★ 1githubgithub.com/cyberharsh/Oracle-mysql-CVE-2012-2122★ 1githubgithub.com/zhangkaibin0921/CVE-2012-2122★ 0githubgithub.com/netw0rk7/CVE-2012-2122-Home-Lab★ 0githubgithub.com/K3ysTr0K3R/CVE-2012-2122★ 0cve_referencewww.exploit-db.com/exploits/19092não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://bugs.mysql.com/bug.php?id=64884http://kb.askmonty.org/en/mariadb-5162-release-notes/http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.htmlhttps://community.rapid7.com/community/metasploit/blog/2012/06/11/cve-2012-2122-a-tragically-comedic-security-flaw-in-mysqlhttp://seclists.org/oss-sec/2012/q2/493http://secunia.com/advisories/49417http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://securitytracker.com/id?1027143http://www.exploit-db.com/exploits/19092http://www.securityfocus.com/bid/53911