10
CVSSv2

CVE-2006-0685

Published: 15/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and previous versions does not exit when authentication fails, which allows remote malicious users to gain unauthorized access.

Vulnerable Product Search on Vulmon Subscribe to Product

virtual hosting control system virtual hosting control system

Exploits

source: wwwsecurityfocuscom/bid/16600/info Virtual Hosting Control System (VHCS) is prone to multiple input and access vulnerabilities VHCS is prone to an HTML-injection vulnerability and an authentication-bypass vulnerability These issues could be exploited to gain administrative access to the application; other attacks are also pos ...