Description
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2007-3998)
qdPM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-45856)
Joomla! Core 3.0.x Information Disclosure (3.0.0 - 3.0.2)
WordPress Plugin DVS Custom Notification Multiple Cross-Site Request Forgery Vulnerabilities (1.0.1)