CVE-2002-1145
published 2002-10-28CVE-2002-1145: The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.34%
94.3th percentile
The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | data_engine | — | — |
| microsoft | data_engine | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=103487044122900&w=2http://marc.info/?l=ntbugtraq&m=103486356413404&w=2http://www.cisco.com/warp/public/707/cisco-sa-20030126-ms02-061.shtmlhttp://www.iss.net/security_center/static/10388.phphttp://www.nextgenss.com/advisories/mssql-webtasks.txthttp://www.securityfocus.com/bid/5980https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-061http://marc.info/?l=bugtraq&m=103487044122900&w=2http://marc.info/?l=ntbugtraq&m=103486356413404&w=2http://www.cisco.com/warp/public/707/cisco-sa-20030126-ms02-061.shtmlhttp://www.iss.net/security_center/static/10388.phphttp://www.nextgenss.com/advisories/mssql-webtasks.txthttp://www.securityfocus.com/bid/5980https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-061
2002-10-28
Published