Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0033.html | Vendor Advisory |
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q248840 | Patch Vendor Advisory |
http://online.securityfocus.com/advisories/3843 | Vendor Advisory |
http://www.securityfocus.com/bid/3998 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8048 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-12-30 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2002-1769
Mitre link : CVE-2002-1769
JSON object : View
CWE
Products Affected
microsoft
- site_server
- site_server_commerce