MS00-035: MS SQL7.0 Service Pack may leave passwords on system (263968)

This script is Copyright (C) 2003-2015 Tenable Network Security, Inc.

Synopsis :

The remote SQL server is vulnerable to an information disclosure

Description :

The installation process of the remote MS SQL server left a file named
'sqlsp.log' on the remote host. This file contains the password
assigned to the 'sa' account of the remote database.

An attacker may use this flaw to gain administrative access to the
database server.

See also :

Solution :

Apply the appropriate patches from MS00-035 or upgrade MS SQL.

Risk factor :

Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 3.9
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 11330 ()

Bugtraq ID: 1281

CVE ID: CVE-2000-0402

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial