PT-2002-1951 · Lugiment · Lugiment Log Explorer

Publicado

2002-08-31

·

Atualizado

2008-09-05

·

CVE-2002-0942

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Lugiment Log Explorer versions prior to 3.02
Description: The issue allows attackers with database permissions to execute arbitrary code via long arguments to the extended stored procedures, specifically (1) xp logattach StartProf, (2) xp logattach setport, or (3) xp logattach.
Recommendations: For versions prior to 3.02, update to version 3.02 or later to resolve the issue. As a temporary workaround, consider restricting access to the extended stored procedures xp logattach StartProf, xp logattach setport, and xp logattach to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0942

Produtos afetados

Lugiment Log Explorer