CVE Database
/

CVE-2003-0148

Back to search

CVE-2003-0148

Published: Aug 1, 2003

Modified: Aug 8, 2024

PUBLISHED

Description

The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.

VendorProductVersions

n/a

n/a

affected
n/a

References

A073103-1
vendor-advisory
x_refsource_ATSTAKE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now