CVE-2002-0645
Microsoft SQL Server 2000 and MSDE 2000 - Authenticated SQL Injection via Stored Procedures
Title source: llmDescription
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-038
Scores
EPSS
0.0384
EPSS Percentile
89.1%
Details
Status
published
Products (2)
microsoft/data_engine
2000
microsoft/sql_server
2000
Published
Aug 12, 2002
Tracked Since
Feb 18, 2026