CVE-2002-0736

Microsoft BackOffice <4.5 - Auth Bypass

Title source: llm
STIX 2.1

Description

Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.

References (4)

Core 4
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-04/0208.html
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8862.php
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/support/kb/articles/q316/8/38.asp
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4528

Scores

EPSS 0.3157
EPSS Percentile 98.1%

Details

Status published
Products (2)
microsoft/backoffice 4.0
microsoft/backoffice 4.5
Published Aug 12, 2002
Tracked Since Feb 18, 2026