Vulnerabilities > CVE-2003-1341 - Configuration vulnerability in Trend Micro Officescan and Virus Buster

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
trend-micro
CWE-16
exploit available

Summary

The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionTrend Micro OfficeScan 3.x CGI Directory Insufficient Permissions Vulnerability. CVE-2003-1341. Remote exploit for windows platform
idEDB-ID:22171
last seen2016-02-02
modified2003-01-15
published2003-01-15
reporterRod Boron
sourcehttps://www.exploit-db.com/download/22171/
titleTrend Micro OfficeScan 3.x CGI Directory Insufficient Permissions Vulnerability