The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-043: Cumulative Patch for SQL Server (Q316333)
Time: 00:02 EST/05:02 GMT | News Source: ActiveWin.com | Posted By: Robert Stein

This is a cumulative patch that includes the functionality of all previously released patches for SQL Server 7.0 and SQL Server 2000. In addition, it eliminates a newly discovered vulnerability. SQL Server 7.0 and SQL Server 2000 provide for extended stored procedures, which are external routines written in programming languages such as C or C#. These procedures appear as normal stored procedures to users and can be invoked and executed just like normal stored procedures. By default, SQL Server 7.0 and SQL Server 2000 ship with a number of extended stored procedures which are used for various helper functions

Some of the Microsoft-provided extended stored procedures that have the ability to reconnect to the database as the SQL Server service account have a flaw in common – namely, they have weak permissions that can allow non-privileged users to execute them. Because these extended stored procedures can be made to run with administrator privileges on the database, it is thus possible for a non-privileged user to run stored procedures on the database with administrator privileges. An attacker could exploit this vulnerability in one of two ways. The attacker could attempt to load and execute a database query that calls one of the affected extended store procedures. Alternately, if a web-site or other database front-end were configured to access and process arbitrary queries, it could be possible for the attacker to provide inputs that would cause the query to call one of the functions in question with the appropriate malformed parameters.

Write Comment
Return to News

  Displaying 701 through 701 of 701
Prev | First
  The time now is 9:36:42 AM ET.
Any comment problems? E-mail us
#701 By 4240821 (85.195.101.122) at 11/23/2025 8:52:46 PM
https://lustful.su/activf4h1321a2h
https://sexonly.top/activh4341gahe1
https://smutty.su/activebc2c5534d
https://sexonly.su/activ15af44e322
https://nsfw.su/activgabah4cehb
https://nsfw.su/activ2eg52d24f4
https://smutty.su/activ34bf514fa3
https://sexonly.su/activbd4hce5bbe
https://sexonly.su/activ3hc3hefa2h
https://lustful.su/activbfe34h42b4

Write Comment
Return to News
  Displaying 701 through 701 of 701
Prev | First
  The time now is 9:36:42 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *