← back
CVE-2005-4145

CVE-2005-4145

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 44%
from disclosure to weapon1745 days
Published on NVDDec 10
1st PoC+1745d
metasploitDec 8
exploitation probability
44%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.