CVE-2002-1981
published 2002-12-31CVE-2002-1981: Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
4.58%
90.5th percentile
Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sql_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Improper Privilege Management
mitre_cwe
CWE-269 Improper Privilege Management
CWE-269: Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Operation
Common Consequences:
Scope: Access Control. Impact: Gain Privileges or Assume Identity.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and contro
CWE
Privilege Defined With Unsafe Actions
mitre_cwe·CVSS 5.0
[MEDIUM] CWE-267 Privilege Defined With Unsafe Actions
CWE-267: Privilege Defined With Unsafe Actions
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Operation
Common Consequences:
Scope: Access Control. Impact: Gain Privileges or Assume Identity. A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Potential Mitigations:
[Architecture and Design] Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the softwar
http://seclists.org/lists/bugtraq/2002/Sep/0009.htmlhttp://www.iss.net/security_center/static/10012.phphttp://www.ngssoftware.com/advisories/mssql-sp_MSSetServerProperties.txthttp://www.securityfocus.com/bid/5604http://seclists.org/lists/bugtraq/2002/Sep/0009.htmlhttp://www.iss.net/security_center/static/10012.phphttp://www.ngssoftware.com/advisories/mssql-sp_MSSetServerProperties.txthttp://www.securityfocus.com/bid/5604
2002-12-31
Published