20031128 Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)mailing list
http://marc.info/?l=bugtraq&m=107004362416252&w=2 CVE-2003-0974
Applied Watch Command Center 1.0 - Authentication Bypass (1)
Record summary
CVE-2003-0974 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) add spurious IDS rules to sensors, as demonstrated using addrule.c.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBApplied Watch Command Center 1.0 - Authentication Bypass (1)ExploitDB exploitby Bugtraq SecurityNot analyzed1 file
ExploitDBApplied Watch Command Center 1.0 - Authentication Bypass (2)ExploitDB exploitby Bugtraq SecurityNot analyzed1 file
References
620031128 Applied Watch Response to Bugtraq.org post - Was: Multiple Remote Issues in Applied Watch IDS Suitemailing list
http://marc.info/?l=bugtraq&m=107005523025918&w=2 20031201 Re: Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)mailing list
http://marc.info/?l=bugtraq&m=107031196324376&w=2 bugtraq.org
http://www.bugtraq.org/advisories/_BSSADV-0000.txt 9124vdb entry
http://www.securityfocus.com/bid/9124 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0974