Opty-Way Enterprise includes MSDE with sa <blank>

From: Philippe de Brito (le_mamousseat_private)
Date: Wed May 22 2002 - 10:07:38 PDT

  • Next message: Johnathan Nightingale: "Multiple Vulnerabilities in CISCO VoIP Phones"

    Opty-Way Enterprise is an industrial soft for cutting
    management.
    
    The package installs MSDE on server side, leaving sa
    account with blank password, thus allowing remote
    launch of xp_cmdshell.
    
    Vendor status: informed March 15, 2002.
    Action taken: none before outbreak of SQLSpida.
    (sigh)
    
    -- 
    le mamousse
    ~Nous sommes venus en paix~
    
    ___________________________________________________________
    Do You Yahoo!? -- Une adresse @yahoo.fr gratuite et en français !
    Yahoo! Mail : http://fr.mail.yahoo.com
    



    This archive was generated by hypermail 2b30 : Wed May 22 2002 - 13:16:22 PDT