Vulnerabilities > CVE-2002-1145 - Unspecified vulnerability in Microsoft Data Engine and SQL Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Nessus
NASL family | Databases |
NASL id | MSSQL_LITCHFIELD_OVERFLOWS.NASL |
description | The remote MS SQL server is affected by several overflows that could be exploited by an attacker to gain SYSTEM access on that host. Note that a worm (sapphire) is exploiting these vulnerabilities in the wild. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11214 |
published | 2003-01-25 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11214 |
title | MS02-061: Microsoft SQL Server Multiple Vulnerabilities (uncredentialed check) |
code |
|
References
- http://www.iss.net/security_center/static/10388.php
- http://www.nextgenss.com/advisories/mssql-webtasks.txt
- http://www.securityfocus.com/bid/5980
- http://www.cisco.com/warp/public/707/cisco-sa-20030126-ms02-061.shtml
- http://marc.info/?l=bugtraq&m=103487044122900&w=2
- http://marc.info/?l=ntbugtraq&m=103486356413404&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-061