Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-1138
Description:Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-1138
Computer Incident Advisory Center Bulletin: N-003
http://www.ciac.org/ciac/bulletins/n-003.shtml
Microsoft Security Bulletin: MS02-056
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-056
XForce ISS Database: mssql-agent-create-files(10257)
http://www.iss.net/security_center/static/10257.php




© 1998-2025 E-Soft Inc. All rights reserved.