5
CVSSv2

CVE-2015-3001

Published: 08/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SysAid Help Desk prior to 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

Vulnerable Product Search on Vulmon Subscribe to Product

sysaid sysaid

Exploits

>> Multiple vulnerabilities in SysAid Help Desk 144 >> Discovered by Pedro Ribeiro (pedrib@gmailcom), Agile Information Security ================================================================================= Disclosure: 03/06/2015 / Last updated: 10/06/2015 >> Background on the affected product: "SysAid is an ITSM solution t ...
SysAid Help Desk version 144 suffers from code execution, denial of service, path disclosure, remote file upload, remote SQL injection, directory traversal, file download, and various other vulnerabilities ...