The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.
Loading...
Loading...
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.
May 30, 2000
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (2 Metasploit modules) (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Microsoft SQL Server - Payload Execution (via SQL Injection) (Metasploit)
Open source ↗Microsoft SQL Server - Payload Execution (Metasploit)
Open source ↗Microsoft SQL Server Payload Execution via SQL Injection
Open source ↗Microsoft SQL Server Payload Execution
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2000-0402
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.