CVE-2002-0187 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 13.9% (pctl 96)
Patch early
A public exploit exists.
Description
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 13.89% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-07-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | sql server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft SQL Server 2000 - SQLXML Script Injection | 2002-06-12 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0100.html
- http://marc.info/?l=bugtraq&m=102397345410856&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-030
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0100.html
- http://marc.info/?l=bugtraq&m=102397345410856&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-030
→ the Explorer · watch your stack · NVD