First published: Fri Aug 23 2002(Updated: )
Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =2000-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0982 has a high severity due to its potential for remote code execution.
To fix CVE-2002-0982, ensure that SQL Server 2000 SP2 is updated to a version that is not vulnerable.
CVE-2002-0982 specifically affects Microsoft SQL Server 2000 SP2 when configured as a distributor.
CVE-2002-0982 can be exploited to execute arbitrary code on the affected SQL Server instance.
CVE-2002-0982 is primarily a concern for legacy systems still using Microsoft SQL Server 2000 SP2.