PT-2002-1260 · Microsoft · Sql Server 2000
Published
2002-07-03
·
Updated
2018-10-12
·
CVE-2002-0186
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server 2000
Description
A buffer overflow issue exists in the SQLXML ISAPI extension, allowing remote attackers to execute arbitrary code through data queries with a long
content-type parameter.Recommendations
For Microsoft SQL Server 2000, apply the necessary patch to fix the buffer overflow issue in the SQLXML ISAPI extension. As a temporary workaround, consider restricting access to the SQLXML ISAPI extension to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sql Server 2000