Files
CVEs-PoC/2009/CVE-2009-3548.md
T
2024-06-18 02:51:15 +02:00

19 lines
783 B
Markdown

### [CVE-2009-3548](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3548)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
### POC
#### Reference
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
#### Github
- https://github.com/cocomelonc/vulnexipy