CVE-2002-0721
high · 10Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
10
CVSS
46.3%
EPSS (exploit prob.)
99th
EPSS percentile
2002-09-05
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | data_engine | 1.0 |
| microsoft | data_engine | 2000 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0087.html
- http://marc.info/?l=bugtraq&m=102950473002959&w=2
- http://marc.info/?l=ntbugtraq&m=102950792606475&w=2
- http://www.kb.cert.org/vuls/id/399531
- http://www.kb.cert.org/vuls/id/818939
- http://www.kb.cert.org/vuls/id/939675
- http://www.ngssoftware.com/advisories/mssql-esppu.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-043
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0087.html
- http://marc.info/?l=bugtraq&m=102950473002959&w=2
- http://marc.info/?l=ntbugtraq&m=102950792606475&w=2
- http://www.kb.cert.org/vuls/id/399531
- http://www.kb.cert.org/vuls/id/818939
- http://www.kb.cert.org/vuls/id/939675
- http://www.ngssoftware.com/advisories/mssql-esppu.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-043
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-0721