Record summary

CVE-2003-0496 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.

Description

Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBMicrosoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (1)ExploitDB exploitby MaceoNot analyzed1 file
ExploitDB

PoC details
ExploitDBMicrosoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (2)ExploitDB exploitby MaceoNot analyzed1 file
ExploitDB

PoC details

References

5