Microsoft SQL Server Enterprise Manager Password Disclosure Vulnerability
BID:1466
Info
Microsoft SQL Server Enterprise Manager Password Disclosure Vulnerability
| Bugtraq ID: | 1466 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 11 2000 12:00AM |
| Updated: | Jul 11 2000 12:00AM |
| Credit: | This vulnerability was discussed in an update to the Microsoft Security Advisory MS00-041. |
| Vulnerable: |
Microsoft SQL Server 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server Enterprise Manager Password Disclosure Vulnerability
Microsoft SQL Server 7.0 Enterprise Manager is vulnerable to a password disclosure vulnerability similar to that described in BugTraq ID 1292. The Registered Servers dialogue can contain a password field with the password "hidden" by asterisks. It is trivial to obtain the otherwise unprotected password; a number of free utilities exist which can accomplish this.
Microsoft SQL Server 7.0 Enterprise Manager is vulnerable to a password disclosure vulnerability similar to that described in BugTraq ID 1292. The Registered Servers dialogue can contain a password field with the password "hidden" by asterisks. It is trivial to obtain the otherwise unprotected password; a number of free utilities exist which can accomplish this.
Exploit / POC
Microsoft SQL Server Enterprise Manager Password Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft SQL Server Enterprise Manager Password Disclosure Vulnerability
Microsoft SQL Server 7.0
Microsoft SQL Server 7.0
-
Microsoft DTSUIa
Alpha
http://download.microsoft.com/download/sql70/DTSPWFix/7.0/ALPHA/EN-US/ DTSUIa.exe -
Microsoft DTSUIi
Intel
http://download.microsoft.com/download/sql70/DTSPWFix/7.0/WIN98/EN-US/ DTSUIi.exe
References
Microsoft SQL Server Enterprise Manager Password Disclosure Vulnerability
References:
References: