7.5
CVSSv2

CVE-2006-3425

Published: 07/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

FastPatch for (a) PatchLink Update Server (PLUS) prior to 6.1 P1 and 6.2.x prior to 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and previous versions, does not require authentication for dagent/proxyreg.asp, which allows remote malicious users to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

lumension patchlink update server 6.2.0.189

novell zenworks

lumension patchlink update server 6.1

lumension patchlink update server 6.2.0.181