RULE(RULE ID:1605101)

Rule General Information
Release Date: 2013-10-16
Rule Name: Microsoft SQL Server 7.0 Log File Plaintext Information Disclosure Vulnerability (CVE-2000-0402)
Severity:
CVE ID:
Rule Protection Details
Description: The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:ms00-035
http://www.microsoft.com/technet/support/kb.asp?ID=263968
SecurityFocusBID:1281
Solutions
Microsoft has released a patch MS00-035 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms00-035.asp