Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted password.
Link | Tags |
---|---|
http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=318 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7286 | vdb entry |
http://www.securityfocus.com/archive/1/220666 | mailing list patch vendor advisory |