20030114 Assorted Trend Vulns Rev 2.0mailing list
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html CVE-2003-1341
Trend Micro OfficeScan 3.x - CGI Directory Insufficient Permissions
Record summary
CVE-2003-1341 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTrend Micro OfficeScan 3.x - CGI Directory Insufficient PermissionsExploitDB exploitby Rod BoronNot analyzed1 file
References
7kb.trendmicro.comConfirmation
http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353 7881Third-party advisory
http://secunia.com/advisories/7881 6181vdb entry
http://www.osvdb.org/6181 6616vdb entry
http://www.securityfocus.com/bid/6616 officescan-cgichkmasterpwd-auth-bypass(11059)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/11059 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-1341