← All CVEs

CVE-2002-0187

high · 7.5

Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."

7.5
CVSS
13.9%
EPSS (exploit prob.)
96th
EPSS percentile
2002-07-03
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
microsoftsql_server2000
microsoftsql_server2000
microsoftsql_server2000

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0187