CVE-2007-3455 Information

Description

cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string related to \stored decrypted user logon information.\

Reference

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=558 http://osvdb.org/36628 http://secunia.com/advisories/25778 http://www.securityfocus.com/bid/24641 http://www.securityfocus.com/bid/24935 http://www.securitytracker.com/id?1018320 http://www.trendmicro.com/ftp/documentation/readme/osce_80_win_en_securitypatch_b1042_readme.txt http://www.vupen.com/english/advisories/2007/2330 https://exchange.xforce.ibmcloud.com/vulnerabilities/35052

Share on: