CVE-2001-1106
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.4%
from disclosure to weapon0 days
Published on NVDApr 2
1st PoCJul 25
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21027⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.