7.5
CVSSv2

CVE-2006-2531

Published: 22/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote malicious users to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".

Vulnerable Product Search on Vulmon Subscribe to Product

ipswitch whatsup professional_2006

Exploits

source: wwwsecurityfocuscom/bid/18019/info Ipswitch WhatsUp Professional 2006 is susceptible to a remote authentication-bypass vulnerability This issue allows remote attackers to gain administrative access to the web-based administrative interface of the application This will aid them in further network attacks The HTTP requests cont ...