Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
| Software | From | Fixed in |
|---|---|---|
| microsoft / sql_server | 7.0-sp1 | 7.0-sp1.x |
| microsoft / sql_server | 2000-sp2 | 2000-sp2.x |
| microsoft / sql_server | 7.0 | 7.0.x |
| microsoft / sql_server | 2000 | 2000.x |
| microsoft / sql_server | 2000-sp1 | 2000-sp1.x |
| microsoft / sql_server | 6.0 | 6.0.x |
| microsoft / sql_server | 7.0-sp3 | 7.0-sp3.x |
| microsoft / sql_server | 7.0-sp4 | 7.0-sp4.x |
| microsoft / sql_server | 6.5 | 6.5.x |
| microsoft / sql_server | 7.0-sp2 | 7.0-sp2.x |