CVE-2012-2122 is an authentication-bypass vulnerability in the password token comparison logic in MySQL and MariaDB. A return value from memcmp is improperly handled during authentication. On affected environments whose memcmp implementation can return values that are truncated or otherwise misinterpreted by the comparison logic, an incorrect password token can be treated as valid. Repeated authentication attempts using the same invalid password can eventually produce a comparison result that is accepted. Affected releases include MySQL 5.1 before 5.1.63, 5.5 before 5.5.24, and 5.6 before 5.6.6, and MariaDB 5.1 before 5.1.62, 5.2 before 5.2.12, 5.3 before 5.3.6, and 5.5 before 5.5.23.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone PoC for CVE-2012-2122, consisting of a README and a single Python exploit script. The README explains the MySQL authentication bypass vulnerability, affected versions, attack prerequisites, impact, and example usage. The exploit logic is entirely in exploit.py. The Python script uses the PyMySQL client library to repeatedly attempt authentication to a target MySQL server with a known username and an intentionally incorrect password. Because CVE-2012-2122 is probabilistic, the script loops up to a configurable number of attempts (default 1500) with a short delay between tries. On successful bypass, it opens a live database connection and executes "SELECT User, Password FROM mysql.user;" to dump account names and password hashes. It prints the results to the console, normalizes hash formatting with a leading asterisk, and writes the extracted credentials to mysql_hashes.txt. Main capabilities: network-based authentication bypass attempt against MySQL/MariaDB, post-authentication enumeration of mysql.user, credential hash dumping, and local persistence of dumped hashes. The script also handles common operational errors, including repeated connection failures and host blocking due to too many connection errors. It is not a detection-only script and does contain active exploitation behavior with a basic post-exploitation action, making it an operational PoC rather than a framework-integrated or heavily weaponized exploit.
This repository contains a single Metasploit auxiliary scanner module targeting MySQL and MariaDB servers vulnerable to CVE-2012-2122, an authentication bypass flaw. The module attempts to exploit the vulnerability by repeatedly attempting to authenticate with a random password, leveraging a flaw that allows authentication to succeed if the server incorrectly processes the password check. Upon successful authentication, the module queries the 'mysql.user' table to extract all usernames and password hashes, which are then saved as loot for later password cracking. The exploit is operational and requires the target to be running a vulnerable version of MySQL or MariaDB and to be accessible over the network. The main attack vector is network-based, targeting the MySQL TCP service (default port 3306). The code is written in Ruby and is structured as a typical Metasploit module, with clear separation of connection logic, exploitation, and data extraction.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.