CVE-2002-0645: SQL Injection
Published Jul 26, 2002
·Updated
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
Affected Software
2 affected components
Microsoft SQL Server=2000
Microsoft Data Engine=2000
Event History
Jul 26, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0645?
CVE-2002-0645 is classified as a medium severity vulnerability.
2
How do I fix CVE-2002-0645?
To fix CVE-2002-0645, you should apply the latest security patches provided by Microsoft for SQL Server 2000 and MSDE 2000.
3
Who is affected by CVE-2002-0645?
CVE-2002-0645 affects authenticated users of Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000.
4
What type of vulnerability is CVE-2002-0645?
CVE-2002-0645 is an SQL injection vulnerability in stored procedures.
5
What can an attacker do with CVE-2002-0645?
An attacker exploiting CVE-2002-0645 can execute arbitrary commands on the affected database system.