CNCVE编号:CNCVE-20010372 CVE编号:CAN-2001-0372 安全级别:高 漏洞中文描述: Akopia Interchange 4.5.3到4.6.3版本用默认的组帐户:backup(没有口令)来安装演示存储,这允许远程攻击者通过演示存储:barry、basic或construct来获得管理员权限。 漏洞英文描述: Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct. 漏洞参考: BUGTRAQ:20010323 FW: Akopia Interchange E-commerce Package Demo Files Vulnerability URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0337.html BID:2499 URL:http://www.securityfocus.com/bid/2499 XF:akopia-interchange-gain-access URL:http://x 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:配置错误