AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs. Fixed in EventLog Analyzer Build 6000.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/42423 | vdb entry |
http://forums.adventnet.com/viewtopic.php?t=247521 | |
http://www.securityfocus.com/bid/26304 | vdb entry |
http://secunia.com/advisories/27833 | third party advisory |