vendor:
ListManager
by:
hdm
7.5
CVSS
HIGH
Weak Password
287
CWE
Product Name: ListManager
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: 2005-4145
CPE: a:lyris:listmanager
Platforms Tested: Windows
2005
Lyris ListManager MSDE Weak sa Password
This module exploits a weak password vulnerability in the Lyris ListManager MSDE install. During installation, the 'sa' account password is set to 'lminstall'. Once the install completes, it is set to 'lyris' followed by the process ID of the installer. This module brute forces all possible process IDs that would be used by the installer.
Mitigation:
Change the default password for the 'sa' account during installation.