Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-0643

EPSS 0.53% · P67
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-0643

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft MS-SQL Server安装过程中明文缓存口令漏洞(MS02-035)
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft SQL Server 7.0/2000是微软公司开发和维护的商业SQL数据库系统。 Microsoft SQL Server安装过程中存在漏洞,本地攻击者可能利用此问题得到访问数据库的认证信息。 在MS-SQL Server 7.0/2000(包括MSDE 1.0)的安装或打服务补丁过程中,相关的信息包括口令会被收集并存放在主机上的一个名为"setup.iss"的文件中。在SQL Server 7.0和MSDE 1.0中此文件位于%windir%目录(默认为C:\Winnt),在SQL
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-0643

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-0643

登录查看更多情报信息。

Same Patch Batch · n/a · 2002-07-12 · 7 CVEs total

CVE-2002-0624Microsoft SQL Server 2000口令加密过程远程缓冲区溢出漏洞(MS02-034)
CVE-2002-0641Microsoft SQL Server 2000多个缓冲区溢出漏洞
CVE-2002-0677多家厂商CDE ToolTalk数据库服务程序远程NULL写漏洞
CVE-2002-0680GoAhead Web Server目录遍历漏洞
CVE-2002-0681GoAhead WebServer出错页面绕过站点脚本漏洞
CVE-2002-0683Pacific Software Carello Shopping Cart Carello.DLL远程命令执行漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2002-0643

No comments yet


Leave a comment