Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://secunia.com/advisories/7881 | third party advisory vendor advisory |
http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11061 | vdb entry |
http://www.securityfocus.com/bid/6619 | patch vdb entry exploit |
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html | mailing list |