>> Trend Micro Web Management Authentication Bypass Vulnerability
Title : Trend Micro Web Management Authentication Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-2421 CVE ID : CVE-2008-2433 CWE ID : CWE-331
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-25
Technical Description
A vulnerability has been identified in various Trend Micro products, which could be exploited by attackers to bypass security restrictions and compromise a vulnerable system. This issue is caused due to insufficient entropy in a random session token used to identify an authenticated manager using the web console, which could allow an attacker to impersonate a currently logged on manager and take full control of the Web console.