Description: A vulnerability has been identified in MySQL on Windows systems allowing malicious, local users to see the administrative username and password.
The problem is that no access restrictions are applied to "my.ini" and that the username and password is stored in clear text.
This has been reported to affect MySQL 3 and MySQL 4 on Windows. Unix and Linux based versions are not affected.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.