CVE-2002-0186

Microsoft SQL Server 2000 - Buffer Overflow via Long Content-Type Parameter in SQLXML ISAPI Extension

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0186. PoCs published by Matt Moore.

AI-analyzed exploit summary The provided text describes a buffer overflow vulnerability in the SQLXML ISAPI extension of SQL Server 2000, which can be triggered via a malformed HTTP request. The issue allows an attacker to crash inetinfo.exe by submitting excessive data in the 'contenttype' parameter.

Description

Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."

Exploits (1)

exploitdb WRITEUP VERIFIED
by Matt Moore · textdoswindows
https://www.exploit-db.com/exploits/21540

The provided text describes a buffer overflow vulnerability in the SQLXML ISAPI extension of SQL Server 2000, which can be triggered via a malformed HTTP request. The issue allows an attacker to crash inetinfo.exe by submitting excessive data in the 'contenttype' parameter.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft SQL Server 2000 Gold (SQLXML ISAPI extension)
No auth needed
Prerequisites: SQLXML ISAPI extension enabled on IIS · Access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/811371
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5347
Patch, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0100.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5004
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9328.php
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A484
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A489
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102397345410856&w=2

Scores

EPSS 0.7341
EPSS Percentile 98.8%

Details

Status published
Products (1)
microsoft/sql_server 2000 (3 CPE variants)
Published Jul 03, 2002
Tracked Since Feb 18, 2026