5
CVE-2015-3001
- EPSS 6.82%
- Veröffentlicht 08.06.2015 14:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.82% | 0.932 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://packetstormsecurity.com/files/132138/SysAid-Help-Desk-14.4-Code-Execution-Denial-Of-Service-Traversal-SQL-Injection.html
http://seclists.org/fulldisclosure/2015/Jun/8
http://www.securityfocus.com/archive/1/535679/100/0/threaded
https://www.sysaid.com/blog/entry/sysaid-15-2-your-voice-your-service-desk
http://www.securityfocus.com/bid/75035