avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements.
Link | Tags |
---|---|
http://www.avast.com/eng/avast-4-server-revision-history.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32269 | vdb entry |
http://secunia.com/advisories/24068 | third party advisory |
http://www.vupen.com/english/advisories/2007/0499 | vdb entry |
http://osvdb.org/33114 | vdb entry |
http://www.securityfocus.com/bid/22425 | vdb entry |