7.5
CVSSv2

CVE-2003-1341

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The default installation of Trend Micro OfficeScan 3.0 up to and including 3.54 and 5.x allows remote malicious users to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.

Vulnerable Product Search on Vulmon Subscribe to Product

trend micro officescan 3.1.1

trend micro officescan 3.13

trend micro officescan 3.5

trend micro officescan 3.0

trend micro officescan 3.54

trend micro officescan 3.11

trend micro virus buster 3.52

trend micro virus buster 3.53

trend micro virus buster 3.54

Exploits

source: wwwsecurityfocuscom/bid/6616/info A vulnerability has been reported for Trend Micro OfficeScan that may allow attackers to access programs residing in the cgi directory of the OfficeScan installation xxxx/officescan/cgi/cgiMasterPwdexe ...