VYPR
Unrated severityNVD Advisory· Published Dec 19, 2000· Updated Apr 16, 2026

CVE-2000-0957

CVE-2000-0957

Description

The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.

Affected products

4
  • cpe:2.3:a:pam_mysql:pam_mysql:0.1:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:pam_mysql:pam_mysql:0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pam_mysql:pam_mysql:0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pam_mysql:pam_mysql:0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:pam_mysql:pam_mysql:0.4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.