CVE-2002-0942 describes buffer overflow vulnerabilities in Lumigent Log Explorer versions prior to 3.02. Attackers with database permissions can exploit these flaws by providing excessively long arguments to specific extended stored procedures (xp_logattach_StartProf, xp_logattach_setport, or xp_logattach), leading to arbitrary code execution. This vulnerability carries a CVSS score of 7.5, indicating high severity due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score of 97/100 further emphasizes its critical nature. While not listed in CISA's KEV catalog, exploit code is publicly available on ExploitDB, demonstrating proof-of-concept for two of the affected stored procedures. The CVE has garnered significant community discussion, with more mentions than 99% of all CVEs, suggesting ongoing interest despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.01CPE matchmatch criteria | cpe:2.3:a:lumigent:log_explorer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.