In versions of SQL Server earlier than Release 6.5, Service Pack 5 the extended stored procedure xp_sprintf can be exploited using buffer overflows. An attacker can use xp_sprintf to crash the server or to possibly gain administrator privileges on the system running SQL Server.
In versions of SQL Server earlier than Release 6.5, Service Pack 5 the extended stored procedure xp_sprintf can be exploited using buffer overflows. An attacker can use xp_sprintf to crash the server or to possibly gain administrator privileges on the system running SQL Server.