Multiple Vulnerabilities in Microsoft Content Management Server 2001
Three new vulnerabilities exist in Content Management Server 2001, the most serious of which could give an attacker full control over the server.
August 8, 2002
Reported August 07, 2002, byMicrosoft.
VERSION AFFECTED
Microsoft Content Management Server 2001
DESCRIPTION
Threenew vulnerabilities exist in Content Management Server 2001, the most serious ofwhich could give an attacker full control over the server. These threevulnerabilities consist of a buffer overrun in a low-level function thatperforms user authentication, a SQL injection vulnerability, and two flaws thataffect a function that could let a user upload files to the server.
VENDORRESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-041(Unchecked Buffer in Content Management Server Could Enable Server Compromise)to address this vulnerability and recommends that affected users download andapply the appropriate patch mentioned in the security bulletin.
CREDIT
Discovered by JoaoGouveia.
About the Author
You May Also Like