Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability

Due to inproper permissions verification when submitting a password modify request, a normal user can successfully change any user's Windows 2000 domain login password. This is accomplished if LDAP requests are being made over a SSL session.







 

Privacy Statement
Copyright 2009, SecurityFocus