CVE-2008-5158

Client Software WinCom LPD Total <3.0.2.623 - Auth Bypass

Title source: llm
STIX 2.1

Description

Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to bypass authentication and perform administrative actions via vectors involving "simply skipping the auth stage."

References (7)

Core 7
Core References
Various Sources x_refsource_misc
http://aluigi.org/adv/wincomalpd-adv.txt
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28763
Various Sources x_refsource_misc
http://aluigi.org/poc/wincomalpd.zip
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/487507/100/200/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0410
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27614
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4610

Scores

EPSS 0.0180
EPSS Percentile 75.7%

Details

CWE
CWE-287
Status published
Products (1)
clientsoftware/wincome_mpd_total < 3.0.2.623
Published Nov 18, 2008
Tracked Since Feb 18, 2026