Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-1145
Description:The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-1145
BugTraq ID: 5980
http://www.securityfocus.com/bid/5980
Bugtraq: 20021017 Microsoft SQL Server Webtasks privilege upgrade (#NISR17102002) (Google Search)
http://marc.info/?l=bugtraq&m=103487044122900&w=2
Cisco Security Advisory: 20030203 Microsoft SQL Server 2000 Vulnerabilities in Cisco Products - MS02-061
http://www.cisco.com/warp/public/707/cisco-sa-20030126-ms02-061.shtml
http://www.nextgenss.com/advisories/mssql-webtasks.txt
Microsoft Security Bulletin: MS02-061
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-061
http://marc.info/?l=ntbugtraq&m=103486356413404&w=2
XForce ISS Database: mssql-webtask-gain-privileges(10388)
http://www.iss.net/security_center/static/10388.php




© 1998-2025 E-Soft Inc. All rights reserved.