DB: Microsoft SQL Server Multiple Vulnerabilities

This signature detects attempts to exploit a known vulnerability against Microsoft SQL Server. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.

Affected Products

Microsoft sql_server

References

CVE: CVE-2000-0402

Short Name
DB:MS-SQL:LINKCRAWLER-CE
Severity
Warning
Recommended
False
Recommended Action
None
Category
DB
Keywords
CVE-2000-0402 Microsoft Multiple SQL Server Vulnerabilities
Release Date
08/05/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

Found a potential security threat?