Re: Microsoft SQL Server Agent Jobs Vulnerabilities (#NISR15002002B)

From: Brent Glover (brent.gloverat_private)
Date: Sun Aug 25 2002 - 14:01:12 PDT

  • Next message: Martin Schulze: "[SECURITY] [DSA 147-2] New mailman packages fix cross-site scripting problem"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <015601c244d2$fa6f8a30$2500a8c0@HEPHAESTUS>
    
    IMHO - This is more a human error driven feature than a high risk 
    vulnerability.
    
    Whilst what David says is true - the assumption has been made that a login 
    has access to the "msdb" database by default - this assumption is 
    incorrect.
    
    The only way this vulnerability can be exploited is if a DBA (mad of 
    course ;-)) has given access for a login account to the "msdb" database.
    
    Brent Glover
    Database specialist
    



    This archive was generated by hypermail 2b30 : Mon Aug 26 2002 - 09:06:17 PDT