7.5
CVSSv2

CVE-2006-0684

Published: 15/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and previous versions does not verify the old password when a user changes the password, which may allow remote malicious users to gain unauthorized access.

Vulnerable Product Search on Vulmon Subscribe to Product

virtual hosting control system virtual hosting control system

Exploits

source: wwwsecurityfocuscom/bid/16600/info Virtual Hosting Control System (VHCS) is prone to multiple input and access vulnerabilities VHCS is prone to an HTML-injection vulnerability and an authentication-bypass vulnerability These issues could be exploited to gain administrative access to the application; other attacks are also possi ...