Trend Micro OfficeScan...

- AV AC AU C I A
发布: 2000-03-16
修订: 2025-04-13

Trend Micro OfficeScan is an antivirus software program which is deployable across an entire network. During the installation of the management software, the administrator is asked to choose between managing from a webserver or from a fileserver. If the webserver option is chosen, the administrator is given the capability to manage the OfficeScan network through an HTML interface. This can be accessed by requesting the authentication form which is located at http: //target/officescan/. It prompts the user for the admin password, however it is transmitted in plaintext which can be intercepted by any user on the network running a packet sniffer specifically searching for the string "TMLogon=<password>". A larger problem exists in that any user with access to the web server is able to perform administrative functions without any sort of authorization simply by requesting specific URLs. This is accomplished by requesting certain CGI files such as jdkRqNotify.exe. A request for...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息