Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html - | |
References | () http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352 - | |
References | () http://secunia.com/advisories/7881 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/6619 - Exploit, Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/11061 - |
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:46
NVD link : CVE-2003-1343
Mitre link : CVE-2003-1343
CVE.ORG link : CVE-2003-1343
JSON object : View
Products Affected
trend_micro
- scanmail
CWE
CWE-287
Improper Authentication