Back
CVE-2002-0187
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
Published: Jul 3, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
GitHub Security Advisory GHSA-vg32-84gw-2fph
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an...
References (6)
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0100.html Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=102397345410856&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-030
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0100.html Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=102397345410856&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-030
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
13.89%
Top 4% most likely to be exploited
Threat Score
34.2 / 100
Data Sources
NVD
EPSS
GitHub