MS00-035: MS SQL7.0 Service Pack may leave passwords on system (263968)

This script is Copyright (C) 2003-2017 Tenable Network Security, Inc.

Synopsis :

The remote SQL server is vulnerable to an information disclosure

Description :

The installation process of the remote MS SQL server left a file named
'sqlsp.log' on the remote host. This file contains the password
assigned to the 'sa' account of the remote database.

An attacker may use this flaw to gain administrative access to the
database server.

See also :

Solution :

Apply the appropriate patches from MS00-035 or upgrade MS SQL.

Risk factor :

Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 3.9
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 11330 ()

Bugtraq ID: 1281

CVE ID: CVE-2000-0402

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now