Vulnerability Name: | CVE-2002-0187 (CCN-9329) | ||||||||
Assigned: | 2002-06-12 | ||||||||
Published: | 2002-06-12 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag." | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: VULNWATCH Type: Patch, Vendor Advisory 20020613 [VulnWatch] wp-02-0007: Microsoft SQLXML ISAPI Overflow and Cross Site Scripting Source: MITRE Type: CNA CVE-2002-0187 Source: BUGTRAQ Type: UNKNOWN 20020613 wp-02-0007: Microsoft SQLXML ISAPI Overflow and Cross Site Scripting Source: CCN Type: CERT Advisory CA-2002-22 Multiple Vulnerabilities in Microsoft SQL Server Source: CCN Type: CIAC Information Bulletin M-091 Microsoft Unchecked Buffer in SQLXML Vulnerability Source: CCN Type: US-CERT VU#139931 Microsoft SQLXML HTTP components vulnerable to cross-site scripting via root parameter Source: CCN Type: Microsoft Security Bulletin MS02-030 Unchecked Buffer in SQLXML Could Lead to Code Execution (Q321911) Source: CCN Type: OSVDB ID: 5343 Microsoft SQL Server SQLXML root Parameter XSS Source: CCN Type: BID-5005 Microsoft SQL Server SQLXML Script Injection Vulnerability Source: CCN Type: Westpoint Security Advisory wp-02-0007.txt Microsoft SQLXML ISAPI Overflow and Cross Site Scripting Source: MS Type: UNKNOWN MS02-030 Source: XF Type: UNKNOWN mssql-sqlxml-script-injection(9329) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |