PT-2006-1739 · Vhcs · Virtual Hosting Control System

Román Medina-Heigl Hernández

+1

·

Published

2006-02-15

·

Updated

2018-10-19

·

CVE-2006-0685

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Virtual Hosting Control System (VHCS) versions 2.4.7.1 and earlier
Description The issue concerns the check login function in login.php, which does not properly exit when authentication fails. This allows remote attackers to gain unauthorized access.
Recommendations For Virtual Hosting Control System (VHCS) versions 2.4.7.1 and earlier, as a temporary workaround, consider disabling the check login function until a patch is available. Restrict access to the login.php module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0685

Affected Products

Virtual Hosting Control System