This script is Copyright (C) 2003-2015 Tenable Network Security, Inc.
The remote SQL server is vulnerable to an information disclosure
The installation process of the remote MS SQL server left a file named
'sqlsp.log' on the remote host. This file contains the password
assigned to the 'sa' account of the remote database.
An attacker may use this flaw to gain administrative access to the
See also :
Apply the appropriate patches from MS00-035 or upgrade MS SQL.
Risk factor :
Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 3.9
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 11330 ()
Bugtraq ID: 1281
CVE ID: CVE-2000-0402
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.