7.5
CVSSv2

CVE-2002-0982

Published: 24/09/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Microsoft SQL Server 2000 SP2, when configured as a distributor, allows malicious users to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft sql server 2000

Exploits

source: wwwsecurityfocuscom/bid/5309/info The Microsoft SQL Server 2000 sp_MScopyscript stored procedure does not sufficiently validate input before passing it to the xp_cmdshell extended stored procedure An attacker with the ability to execute a query or pass malicious input to a query may be able to execute operating system commands vi ...