Remote Compromise Vulnerability in Macromedia Dreamweaver

A potential attacker can gain access to the back-end database server without supplying a user ID and password.

Ken Pfeil

April 6, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported April 5, 2004, by NGSSoftware.

 

 

VERSIONS AFFECTED

 

  • Dreamweaver MX 2004 (all versions)

  • Dreamweaver MX (all versions)

  • Dreamweaver UltraDev 4 (all versions)

 

DESCRIPTION

 

Dreamweaver by default creates and uploads a script to test remote database connectivity (mmhttpdb.asp) to the database-driven Web site being tested. If left on the server, the script can let a potential attacker access to the back-end database server without supplying a user ID and password.

 

 

VENDOR RESPONSE

 

The vendor,Macromedia, has released analert about this vulnerability.

 

CREDIT                                                                                                       

 

Discovered byNGSSoftware.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like