7.5
CVSSv2

CVE-2011-0434

Published: 07/03/2011 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) prior to 0.32.9 allow remote malicious users to execute arbitrary SQL commands via the cid parameter to (1) admin/bw_per_month.php or (2) client/bw_per_month.php.

Vulnerable Product Search on Vulmon Subscribe to Product

gplhost domain technologie control

gplhost domain technologie control 0.29.8

gplhost domain technologie control 0.28.9

gplhost domain technologie control 0.32.1

gplhost domain technologie control 0.25.3

gplhost domain technologie control 0.30.6

gplhost domain technologie control 0.26.9

gplhost domain technologie control 0.29.1

gplhost domain technologie control 0.27.3

gplhost domain technologie control 0.28.4

gplhost domain technologie control 0.32.3

gplhost domain technologie control 0.28.10

gplhost domain technologie control 0.25.1

gplhost domain technologie control 0.30.18

gplhost domain technologie control 0.26.8

gplhost domain technologie control 0.28.6

gplhost domain technologie control 0.28.2

gplhost domain technologie control 0.32.2

gplhost domain technologie control 0.29.14

gplhost domain technologie control 0.29.17

gplhost domain technologie control 0.26.7

gplhost domain technologie control 0.29.16

gplhost domain technologie control 0.30.10

gplhost domain technologie control 0.32.6

gplhost domain technologie control 0.29.6

gplhost domain technologie control 0.28.3

gplhost domain technologie control 0.24.6

gplhost domain technologie control 0.32.5

gplhost domain technologie control 0.29.15

gplhost domain technologie control 0.29.10

gplhost domain technologie control 0.30.20

gplhost domain technologie control 0.30.8

gplhost domain technologie control 0.32.7

gplhost domain technologie control 0.32.4

gplhost domain technologie control 0.25.2

Vendor Advisories

Ansgar Burchardt discovered several vulnerabilities in DTC, a web control panel for admin and accounting hosting services CVE-2011-0434 The bw_per_mothphp graph contains an SQL injection vulnerability CVE-2011-0435 Insufficient checks in bw_per_monthphp can lead to bandwidth usage information disclosure CVE-2011-0436 After a r ...