Vulnerabilities > CVE-2015-3001 - Credentials Management vulnerability in Sysaid

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sysaid
CWE-255
exploit available

Summary

SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

Vulnerable Configurations

Part Description Count
Application
Sysaid
4

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionSysAid Help Desk 14.4 - Multiple Vulnerabilities. CVE-2015-2993,CVE-2015-2994,CVE-2015-2995,CVE-2015-2996,CVE-2015-2997,CVE-2015-2998,CVE-2015-2999,CVE-2015-...
idEDB-ID:43885
last seen2018-01-25
modified2015-06-10
published2015-06-10
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43885/
titleSysAid Help Desk 14.4 - Multiple Vulnerabilities

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/132138/sysaidhelpdesk-execdos.txt
idPACKETSTORM:132138
last seen2016-12-05
published2015-06-03
reporterPedro Ribeiro
sourcehttps://packetstormsecurity.com/files/132138/SysAid-Help-Desk-14.4-Code-Execution-Denial-Of-Service-Traversal-SQL-Injection.html
titleSysAid Help Desk 14.4 Code Execution / Denial Of Service / Traversal / SQL Injection