CVE-2002-0736
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/08/2002
Last modified:
03/04/2025
Description
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microsoft:backoffice:4.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:backoffice:4.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0208.html
- http://support.microsoft.com/support/kb/articles/q316/8/38.asp
- http://www.iss.net/security_center/static/8862.php
- http://www.securityfocus.com/bid/4528
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0208.html
- http://support.microsoft.com/support/kb/articles/q316/8/38.asp
- http://www.iss.net/security_center/static/8862.php
- http://www.securityfocus.com/bid/4528



