Microsoft Site Server 3.0默认帐户漏洞

漏洞信息详情

Microsoft Site Server 3.0默认帐户漏洞

漏洞简介

微软站点服务器3.0 SP4之前版本安装默认用户,LDAP_Anonymous,具有LdapPassword_1的默认密码。远程攻击者获得“本地登录”特权。

漏洞公告

SP4 for Site Server 3.0 resolves this issue:
Microsoft Site Server 3.0 alpha

Microsoft Site Server Commerce Edition 3.0 SP2 i386

Microsoft Site Server Commerce Edition 3.0 SP2 alpha

Microsoft Site Server 3.0 SP1 alpha

Microsoft Site Server 3.0 SP2 alpha

Microsoft Site Server Commerce Edition 3.0 SP1 alpha

Microsoft Site Server 3.0 SP1 i386

Microsoft Site Server Commerce Edition 3.0 SP3 alpha

Microsoft Site Server 3.0 i386

Microsoft Site Server 3.0 SP3 alpha

Microsoft Site Server 3.0 SP3 i386

Microsoft Site Server Commerce Edition 3.0 i386

Microsoft Site Server Commerce Edition 3.0 SP3 i386

Microsoft Site Server 3.0 SP2 i386

Microsoft Site Server Commerce Edition 3.0 SP1 i386

Microsoft Site Server Commerce Edition 3.0 alpha

参考网址

来源: XF
名称: siteserver-ldap-anonymous-account(8048)
链接:http://xforce.iss.net/xforce/xfdb/8048

来源: BID
名称: 3998
链接:http://www.securityfocus.com/bid/3998

来源: MSKB
名称: Q248840
链接:http://support.microsoft.com/default.aspx?scid=kb;en-us;Q248840

来源: online.securityfocus.com
链接:http://online.securityfocus.com/advisories/3843

来源: VULNWATCH
名称: 20020129 RFP2201: MS Site Server Evilness
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0033.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享