7.5
CVSSv2

CVE-2001-1106

Published: 25/07/2001 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The default configuration of Sambar Server 5 and previous versions uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.

Vulnerable Product Search on Vulmon Subscribe to Product

sambar sambar server 5.0

sambar sambar server 4.3

sambar sambar server 4.4

sambar sambar server 4.1

sambar sambar server 4.2.1_production

Exploits

source: wwwsecurityfocuscom/bid/3095/info Sambar Server is a multi-threaded HTTP server for Microsoft Windows and Unix systems Sambar Server provides insecure default protection for user passwords The default password decryption algorithm employs only a single key, built into the server binary If the key is recovered, user passwords ...