Total vulnerabilities in the database
Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege.
Software | From | Fixed in |
---|---|---|
microsoft / site_server | 3.0-sp2 | 3.0-sp2.x |
microsoft / site_server | 3.0-sp2_alpha | 3.0-sp2_alpha.x |
microsoft / site_server_commerce | 3.0-sp3_alpha | 3.0-sp3_alpha.x |
microsoft / site_server | 3.0-sp3_alpha | 3.0-sp3_alpha.x |
microsoft / site_server | 3.0-sp1_alpha | 3.0-sp1_alpha.x |
microsoft / site_server | 3.0 | 3.0.x |
microsoft / site_server_commerce | 3.0-sp1_alpha | 3.0-sp1_alpha.x |
microsoft / site_server | 3.0-apha | 3.0-apha.x |
microsoft / site_server | 3.0-sp1 | 3.0-sp1.x |
microsoft / site_server_commerce | 3.0-alpha | 3.0-alpha.x |
microsoft / site_server | 3.0-sp3 | 3.0-sp3.x |
microsoft / site_server_commerce | 3.0-sp2_alpha | 3.0-sp2_alpha.x |
microsoft / site_server_commerce | 3.0 | 3.0.x |