Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-2433
StatusCandidate
DescriptionThe web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks.  NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."
PhaseAssigned (27.05.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2433
ReferencesBID : 30792
 BUGTRAQ : 20080822 Secunia Research: Trend Micro Products Web Management Authentication Bypass
 CONFIRM : http://www.trendmicro.com/ftp/documentation/readme...
 CONFIRM : http://www.trendmicro.com/ftp/documentation/readme...
 MISC : http://secunia.com/secunia_research/2008-31/advisory/
 SECTRACK : 1020732
 SECUNIA : 31373
 SREASON : 4191
 VUPEN : ADV-2008-2421
 XF : trend-micro-token-security-bypass(44597)
SecurityVulns:Trend Micro multiple application authentication bypass

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server