CVE-2000-0937
Samba 2.0.7 - Unauthenticated Brute Force Password Guessing via SWAT Login
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0937. PoCs published by dodeca-T.
AI-analyzed exploit summary This exploit targets a vulnerability in Samba SWAT (CVE-2000-0937) where incorrect password attempts for valid usernames are not logged. The code brute-forces credentials by checking responses to authentication attempts, distinguishing between invalid usernames and incorrect passwords.
Description
Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.
Exploits (1)
This exploit targets a vulnerability in Samba SWAT (CVE-2000-0937) where incorrect password attempts for valid usernames are not logged. The code brute-forces credentials by checking responses to authentication attempts, distinguishing between invalid usernames and incorrect passwords.