Application Security, Inc.
home client login partner login online store contact us
search:
Solutions Products Partners Support News & Events About Us

Security Updates - ASAP™ Updates
(Application Security Automatic Protection)

AppDetective™ Update 2.5.85 - 09 September 2002

NEW CHECKS

Microsoft SQL Server

Title: Permission on mswebtasks
Summary:
The table mswebtasks in the msdb database is used to manage web tasks. By default, permissions on this table are granted to the group public.

Title: Permission on sp_runwebtask
Summary:
The system stored procedure sp_runwebtask in the master database is used to run web tasks. By default, permissions on this system stored procedure are granted to the group public.

Title: Permission on sp_readwebtask
Summary:
The system stored procedure sp_readwebtask in the master database is used to read web tasks. By default, permissions on this system stored procedure are granted to the group public.

Title: Permission on xp_readerrorlog
Summary:
The extended stored procedure xp_readerrorlog in the master database is used to read the log files from Transact SQL. This extended stored procedure can also be used to maliciously read arbitrary files from the operating system.

Return to ASAP™ Updates Listing