---
#This File was made using the WinMySQLadmin 1.1 Tool
[MySQLd]
basedir=C:/MySQL
datadir=C:/MySQL/data
[WinMySQLadmin]
Server=C:/mysql/bin/MySQLd-nt.exe
user=admin
passWord=XXXXX (in clear text)
QueryInterval=30
---
利用此漏洞,如果遠程攻擊者能遍歷受影響系統,將可能取得數據庫管理員權限。如:
http://packetstormsecurity.org/9905-exploits/ms.IIS4.showcode.txt