Select the product you need help with
MS02-030: SQLXML Security UpdatesArticle ID: 321911 - View products that this article applies to. This article was previously published under Q321911 On This PageSUMMARY Microsoft has released a patch for SQLXML that includes
updates for the issues that are described in the following Microsoft Knowledge
Base articles:
321460
(http://support.microsoft.com/kb/321460/
)
FIX: Patch available for script injection with XML tag and unchecked buffer in SQLXML ISAPI extension vulnerabilities
321858
(http://support.microsoft.com/kb/321858/
)
FIX: MDAC: Patch available for script injection with XML tag and unchecked buffer in SQLXML ISAPI extension vulnerabilities
MORE INFORMATION For more information about this patch, visit the following
Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/MS02-030.mspx NOTE: These updates apply to all applicable languages.
(http://www.microsoft.com/technet/security/bulletin/MS02-030.mspx)
MDAC 2.7Download InformationThe following file is available for download from the Microsoft Download Center:Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=cf3f644b-f68f-4ec9-8808-34860f9dc31f&DisplayLang=en)
Release Date: JUN-12-2002 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/
)
How to obtain Microsoft support files from online services
Installation OptionsYou must restart your computer after you apply this update. This update supports the following Setup switches:Switch Description ------------------------------------------------------------------------- /? Displays the list of installation switches /Q Quiet mode /T:<full path> Specifies the temporary working folder /C Extract files only to the folder when used also with /T /C:<Cmd> Override Install Command defined by author Q321858_sql_security_mdac26.exe /C:"dahotfix.exe /q /n" WARNING: Your computer is vulnerable until you restart it. File InformationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.The following files are copied to the Program Files\Common Files\System\Ole DB folder. Date Time Version Size File name ------------------------------------------------------------------ 09-Apr-2002 01:14 2000.80.309.0 53,317 bytes Sqlisapi.dll 04-Apr-2002 21:07 2000.80.605.0 213,072 bytes Sqlxmlx.dll MDAC 2.6Download InformationThe following file is available for download from the Microsoft Download Center:Collapse this image ![]()
(http://www.microsoft.com/downloads/details.aspx?FamilyID=cf3f644b-f68f-4ec9-8808-34860f9dc31f&DisplayLang=en)
Release Date: JUN-12-2002 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/
)
How to obtain Microsoft support files from online services
Installation OptionsYou must restart your computer after you apply this update. This update supports the following Setup switches:Switch Description -------------------------------------------------------------------------- /? Displays the list of installation switches /Q Quiet mode /T:<full path> Specifies the temporary working folder /C Extract files only to the folder when used also with /T /C:<Cmd> Override Install Command defined by author /N No reboot dialog Q321858_sql_security_mdac26.exe /C:"dahotfix.exe /q /n" WARNING: Your computer is vulnerable until you restart it. File InformationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.The following files are copied to the Program Files\Common Files\System\Ole DB folder. Date Time Version Size File name ----------------------------------------------------------------- 09-Apr-2002 01:14 2000.80.309.0 53,317 bytes Sqlisapi.dll 09-Apr-2002 01:14 2000.80.309.0 188,496 bytes Sqlxmlx.dll SQLXML 3.0To resolve this problem, obtain the latest service pack for Microsoft SQL Server 2000. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:290211 NOTE: The following hotfix was created before the release of Microsoft
SQL Server 2000 Service Pack 3.
(http://support.microsoft.com/kb/290211/
)
How to obtain the latest SQL Server 2000 service pack
The following file is available for download from the Microsoft Download Center: Collapse this image ![]()
(https://www.microsoft.com/downloads/details.aspx?FamilyID=05f1a309-be6e-49fe-968d-9833fa15cc12&DisplayLang=en)
Release Date: June-12-2002 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/
)
How to obtain Microsoft support files from online services
Installation OptionsYou must restart your computer after you apply this update. This update supports the following Setup switches:Switch Description ------------------------------------------------------------------------- /? Displays the list of installation switches /Q Quiet mode /T:<full path> Specifies temporary working folder /C Extract files only to the folder when used also with /T /C:<Cmd> Override Install Command defined by author /N No reboot dialog SQLXML3_Q320833 /C:"msiexec /i sqlxml2_Q321460.msp /q" WARNING: Your computer is vulnerable until you restart it. File InformationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.
Version File name
------------------------
3.0.1811.0 Sqlis3.dll
3.0.1811.0 Sqlxml3.dll
Installation OptionsYou must restart your computer after you apply this update. This update supports the following Setup switches:Switch Description ------------------------------------------------------------------------- /? Displays the list of installation switches /Q Quiet mode /T:<full path> Specifies temporary working folder /C Extract files only to the folder when used also with /T /C:<Cmd> Override Install Command defined by author SQLXML2_Q321460 /C:"msiexec /i sqlxml2_Q321460.msp /q" WARNING: Your computer is vulnerable until you restart it. File InformationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.
Version File name
-----------------------
2.0.1804.0 Sqlis2.dll
2.0.1804.0 Sqlxml2.dll
PropertiesArticle ID: 321911 - Last Review: October 10, 2011 - Revision: 10.0 APPLIES TO
| Article Translations
|



Back to the top








