Vulnerability Description
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
CVSS Score
10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Horde | Horde | 3.0.4 |
References
- http://www.debian.org/security/2005/dsa-884PatchVendor Advisory
- http://www.networkscanning.com/Horde-Default-Admin-Password-Vulnerability-VSS_20
- http://www.osvdb.org/24117
- http://www.securityfocus.com/bid/15337/Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24576
- http://www.debian.org/security/2005/dsa-884PatchVendor Advisory
- http://www.networkscanning.com/Horde-Default-Admin-Password-Vulnerability-VSS_20
- http://www.osvdb.org/24117
- http://www.securityfocus.com/bid/15337/Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24576
FAQ
What is CVE-2005-3344?
CVE-2005-3344 is a vulnerability with a CVSS score of 10.0 (HIGH). The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
How severe is CVE-2005-3344?
CVE-2005-3344 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3344?
Check the references section above for vendor advisories and patch information. Affected products include: Horde Horde.