Vulnerabilities > CVE-2002-0721 - Unspecified vulnerability in Microsoft Data Engine and SQL Server
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Exploit-Db
description | Microsoft SQL 2000/7.0 Agent Jobs Privilege Elevation Vulnerability. CVE-2002-0721. Remote exploit for windows platform |
id | EDB-ID:21718 |
last seen | 2016-02-02 |
modified | 2002-08-15 |
published | 2002-08-15 |
reporter | David Litchfield |
source | https://www.exploit-db.com/download/21718/ |
title | Microsoft SQL 2000/7.0 - Agent Jobs Privilege Elevation Vulnerability |
Nessus
NASL family | Databases |
NASL id | MSSQL_LITCHFIELD_OVERFLOWS.NASL |
description | The remote MS SQL server is affected by several overflows that could be exploited by an attacker to gain SYSTEM access on that host. Note that a worm (sapphire) is exploiting these vulnerabilities in the wild. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11214 |
published | 2003-01-25 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11214 |
title | MS02-061: Microsoft SQL Server Multiple Vulnerabilities (uncredentialed check) |
code |
|
References
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0087.html
- http://marc.info/?l=bugtraq&m=102950473002959&w=2
- http://marc.info/?l=ntbugtraq&m=102950792606475&w=2
- http://www.kb.cert.org/vuls/id/399531
- http://www.kb.cert.org/vuls/id/818939
- http://www.kb.cert.org/vuls/id/939675
- http://www.ngssoftware.com/advisories/mssql-esppu.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-043