[25541] in bugtraq
Opty-Way Enterprise includes MSDE with sa
daemon@ATHENA.MIT.EDU (=?iso-8859-1?q?Philippe=20de=20Bri)
Wed May 22 16:08:10 2002
Message-ID: <20020522170738.73959.qmail@web20206.mail.yahoo.com>
Date: Wed, 22 May 2002 19:07:38 +0200 (CEST)
From: =?iso-8859-1?q?Philippe=20de=20Brito?= <le_mamousse@yahoo.fr>
To: bugtraq@securityfocus.com
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Opty-Way Enterprise is an industrial soft for cutting
management.
The package installs MSDE on server side, leaving sa
account with blank password, thus allowing remote
launch of xp_cmdshell.
Vendor status: informed March 15, 2002.
Action taken: none before outbreak of SQLSpida.
(sigh)
--
le mamousse
~Nous sommes venus en paix~
___________________________________________________________
Do You Yahoo!? -- Une adresse @yahoo.fr gratuite et en français !
Yahoo! Mail : http://fr.mail.yahoo.com