Back to search
CVE-2007-3455
Published: Jun 27, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
24641
vdb-entry
x_refsource_BID
24935
vdb-entry
x_refsource_BID
36628
vdb-entry
x_refsource_OSVDB
20070716 Trend Micro OfficeScan Management Console Authorization Bypass Vulnerability
third-party-advisory
x_refsource_IDEFENSE
ADV-2007-2330
vdb-entry
x_refsource_VUPEN
25778
third-party-advisory
x_refsource_SECUNIA
1018320
vdb-entry
x_refsource_SECTRACK
officescan-cgichkmasterpwd-security-bypass(35052)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now