First published: Wed Dec 31 2003(Updated: )
Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Virus Control System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1344 has been classified as a high severity vulnerability due to the potential exposure of sensitive credentials.
To mitigate CVE-2003-1344, it is crucial to restrict access to the getservers.exe file and implement proper authentication controls.
CVE-2003-1344 allows attackers to access usernames, encrypted passwords, and other sensitive information from log files.
CVE-2003-1344 affects Trend Micro Virus Control System installations.
Yes, CVE-2003-1344 can be exploited remotely by sending a specific URL request to the vulnerable application.