10
CVE-2002-1145
- EPSS 1.84%
- Published 28.10.2002 05:00:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Data Engine Version1.0
Microsoft ≫ Data Engine Version2000
Microsoft ≫ Sql Server Version7.0
Microsoft ≫ Sql Server Version7.0 Updatesp1
Microsoft ≫ Sql Server Version7.0 Updatesp2
Microsoft ≫ Sql Server Version7.0 Updatesp3
Microsoft ≫ Sql Server Version7.0 Updatesp4
Microsoft ≫ Sql Server Version2000
Microsoft ≫ Sql Server Version2000 Updatesp1
Microsoft ≫ Sql Server Version2000 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.84% | 0.823 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|