PT-2003-1320 · Protegrity · Protegrity Secure.Data Extension Feature

Sss Sss

·

Publicado

2003-03-14

·

Atualizado

2016-10-18

·

CVE-2003-0030

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Protegrity Secure.Data Extension Feature (SEF) versions prior to 2.2.3.9
Description The issue concerns buffer overflows in the protegrity.dll component, allowing attackers with SQL access to execute arbitrary code. This can be achieved through the extended stored procedures xp pty checkusers, xp pty insert, or xp pty select.
Recommendations For versions prior to 2.2.3.9, update to version 2.2.3.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the extended stored procedures xp pty checkusers, xp pty insert, and xp pty select to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0030

Produtos afetados

Protegrity Secure.Data Extension Feature