10
CVSSv2

CVE-2000-0248

Published: 24/04/2000 Updated: 10/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote malicious users to execute arbitrary commands.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat linux 6.2

Exploits

## # $Id: piranha_passwd_execrb 10729 2010-10-18 15:41:13Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...
source: wwwsecurityfocuscom/bid/1148/info A default username and password has been discovered in the Piranha virtual server and load balancing package from RedHat Version 0412 of the piranha-gui program contains a default account, piranha, with the password 'q' (no quotes) Using this username and password, in conjunction with flaws in ...