7.5
CVSSv2

CVE-2006-6973

Published: 07/02/2007 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote malicious users to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/.

Vulnerable Product Search on Vulmon Subscribe to Product

headstart solutions deskpro