Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-2433
Description:The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."
Test IDs: 1.3.6.1.4.1.25623.1.0.900205  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-2433
BugTraq ID: 30792
http://www.securityfocus.com/bid/30792
Bugtraq: 20080822 Secunia Research: Trend Micro Products Web Management Authentication Bypass (Google Search)
http://www.securityfocus.com/archive/1/495670/100/0/threaded
http://secunia.com/secunia_research/2008-31/advisory/
http://www.securitytracker.com/id?1020732
http://secunia.com/advisories/31373
http://securityreason.com/securityalert/4191
http://www.vupen.com/english/advisories/2008/2421
XForce ISS Database: trend-micro-token-security-bypass(44597)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44597




© 1998-2025 E-Soft Inc. All rights reserved.