Brightmail Control Center Default Account/Password
This script is Copyright (C) 2005-2008 Tenable Network Security, Inc.
Family
General
Plugin ID
19598
Bugtraq ID
CVE ID
Description:
Synopsis :
The remote server uses known authentication credentials.
Description :
The remote host is running Symantecs Brightmail Control Center, a
web-based administration tool for Brightmail AntiSpam.
The installation of Brightmail Control Center on the remote host still
has an account admin with the default password symantec. An
attacker can exploit this issue to gain access of the Control Center
and any scanners it controls.
Solution :
Log in to the Brightmail Control Center and change the password for
the admin user.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)