The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5511 | vdb entry |
http://online.securityfocus.com/archive/1/288105 | mailing list |
http://www.iss.net/security_center/static/9908.php | vdb entry |