Vulnerabilities > CVE-2002-0186 - Unspecified vulnerability in Microsoft SQL Server 2000
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability. CVE-2002-0186. Dos exploit for windows platform |
id | EDB-ID:21540 |
last seen | 2016-02-02 |
modified | 2002-06-12 |
published | 2002-06-12 |
reporter | Matt Moore |
source | https://www.exploit-db.com/download/21540/ |
title | Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-030.NASL |
description | The remote host is running SQLXML. There are flaws in this application that could allow a remote attacker to execute arbitrary code on this host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11304 |
published | 2003-03-02 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11304 |
title | MS02-030: Unchecked Buffer in SQLXML (321911) |
code |
|
Oval
accepted 2005-04-27T12:07:00.000-04:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name Matthew Burton organization The MITRE Corporation name Matthew Burton organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation
description Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension." family windows id oval:org.mitre.oval:def:484 status accepted submitted 2004-09-15T12:00:00.000-04:00 title Unchecked Buffer in SQLXML ISAPI Extension for Microsoft Data Access Components 2.6 version 26 accepted 2005-04-27T12:07:00.000-04:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name Matthew Burton organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation
description Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension." family windows id oval:org.mitre.oval:def:489 status accepted submitted 2004-09-15T12:00:00.000-04:00 title Unchecked Buffer in SQLXML ISAPI Extension for Microsoft Data Access Components 2.7 version 26
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0100.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0100.html
- http://marc.info/?l=bugtraq&m=102397345410856&w=2
- http://marc.info/?l=bugtraq&m=102397345410856&w=2
- http://www.iss.net/security_center/static/9328.php
- http://www.iss.net/security_center/static/9328.php
- http://www.kb.cert.org/vuls/id/811371
- http://www.kb.cert.org/vuls/id/811371
- http://www.osvdb.org/5347
- http://www.osvdb.org/5347
- http://www.securityfocus.com/bid/5004
- http://www.securityfocus.com/bid/5004
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-030
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-030
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A484
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A484
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A489
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A489