Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege.
Link | Tags |
---|---|
http://online.securityfocus.com/advisories/3843 | vendor advisory |
http://www.securityfocus.com/bid/3998 | vdb entry patch |
http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3BQ248840 | vendor advisory |
http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0033.html | mailing list vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8048 | vdb entry |