Multiple Vulnerabilities in Microsoft Content Management Server 2001

Three new vulnerabilities exist in Content Management Server 2001, the most serious of which could give an attacker full control over the server.

Ken Pfeil

August 8, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported August 07, 2002, byMicrosoft.

VERSION AFFECTED

 

  • Microsoft Content Management Server 2001

 

DESCRIPTION

 

Threenew vulnerabilities exist in Content Management Server 2001, the most serious ofwhich could give an attacker full control over the server. These threevulnerabilities consist of a buffer overrun in a low-level function thatperforms user authentication, a SQL injection vulnerability, and two flaws thataffect a function that could let a user upload files to the server.

 

VENDORRESPONSE

 

Thevendor, Microsoft, has released SecurityBulletin MS02-041(Unchecked Buffer in Content Management Server Could Enable Server Compromise)to address this vulnerability and recommends that affected users download andapply the appropriate patch mentioned in the security bulletin.

 

CREDIT
Discovered by JoaoGouveia.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like