CVE-2002-1872

Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:sql_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2000:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2000:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:6.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2000:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:6.0:*:*:*:*:*:*:*

Information

Published : 2002-12-31 05:00

Updated : 2008-09-05 20:31


NVD link : CVE-2002-1872

Mitre link : CVE-2002-1872


JSON object : View

Products Affected

microsoft

  • sql_server