Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft MS-SQL Server安装过程中明文缓存口令漏洞(MS02-035)
Vulnerability Description
Microsoft SQL Server 7.0/2000是微软公司开发和维护的商业SQL数据库系统。 Microsoft SQL Server安装过程中存在漏洞,本地攻击者可能利用此问题得到访问数据库的认证信息。 在MS-SQL Server 7.0/2000(包括MSDE 1.0)的安装或打服务补丁过程中,相关的信息包括口令会被收集并存放在主机上的一个名为"setup.iss"的文件中。在SQL Server 7.0和MSDE 1.0中此文件位于%windir%目录(默认为C:\Winnt),在SQL
CVSS Information
N/A
Vulnerability Type
N/A