| hi, i wonder if this aplies to that vulnerability :
Sql Server 2000 8.00.194
in Mixed Mode
Log in as 'sa'
and then execute SELECT * FROM OPENROWSET('SQLOLEDB','Trusted_Connection=Yes;Data Source=myserver','SET FMTONLY OFF execute master..xp_cmdshell "dir c:\"')
then if you log as a non admin user you can execute exactly the same query no bother if you don't have permission.
Sorry for my inglish.
Thanks.
|