Vulnerability Description
The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mysql | 3.20.32a |
References
- http://online.securityfocus.com/archive/1/288105
- http://www.iss.net/security_center/static/9909.php
- http://www.securityfocus.com/bid/5513
- http://online.securityfocus.com/archive/1/288105
- http://www.iss.net/security_center/static/9909.php
- http://www.securityfocus.com/bid/5513
FAQ
What is CVE-2002-1923?
CVE-2002-1923 is a vulnerability with a CVSS score of 7.5 (HIGH). The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.
How severe is CVE-2002-1923?
CVE-2002-1923 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1923?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Mysql.