PT-2006-3320 · Ipswitch · Ipswitch Whatsup Professional 2006+1

David Maciejak

·

Publicado

2006-05-15

·

Atualizado

2017-12-04

·

CVE-2006-2356

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ipswitch WhatsUp Professional 2006 Ipswitch WhatsUp Professional 2006 Premium
Description The issue allows remote attackers to obtain sensitive information about network nodes. This is achieved by modifying the nDeviceGroupID parameter in the NmConsole/utility/RenderMap.asp file.
Recommendations For Ipswitch WhatsUp Professional 2006, restrict access to the NmConsole/utility/RenderMap.asp file to minimize the risk of exploitation. For Ipswitch WhatsUp Professional 2006 Premium, avoid using the modified nDeviceGroupID parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-2356

Produtos afetados

Ipswitch Whatsup Professional 2006
Ipswitch Whatsup Professional 2006 Premium