4
CVSSv2

CVE-2011-0437

Published: 07/03/2011 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

shared/inc/sql/ssh.php in the SSH accounts management implementation in Domain Technologie Control (DTC) prior to 0.32.9 allows remote authenticated users to delete arbitrary accounts via the edssh_account parameter in a deletesshaccount Delete action.

Vulnerable Product Search on Vulmon Subscribe to Product

gplhost domain technologie control

gplhost domain technologie control 0.29.8

gplhost domain technologie control 0.28.9

gplhost domain technologie control 0.32.1

gplhost domain technologie control 0.25.3

gplhost domain technologie control 0.30.6

gplhost domain technologie control 0.26.9

gplhost domain technologie control 0.29.1

gplhost domain technologie control 0.27.3

gplhost domain technologie control 0.28.4

gplhost domain technologie control 0.32.3

gplhost domain technologie control 0.28.10

gplhost domain technologie control 0.25.1

gplhost domain technologie control 0.30.18

gplhost domain technologie control 0.26.8

gplhost domain technologie control 0.28.6

gplhost domain technologie control 0.28.2

gplhost domain technologie control 0.32.2

gplhost domain technologie control 0.29.14

gplhost domain technologie control 0.29.17

gplhost domain technologie control 0.26.7

gplhost domain technologie control 0.29.16

gplhost domain technologie control 0.30.10

gplhost domain technologie control 0.32.6

gplhost domain technologie control 0.29.6

gplhost domain technologie control 0.28.3

gplhost domain technologie control 0.24.6

gplhost domain technologie control 0.32.5

gplhost domain technologie control 0.29.15

gplhost domain technologie control 0.29.10

gplhost domain technologie control 0.30.20

gplhost domain technologie control 0.30.8

gplhost domain technologie control 0.32.7

gplhost domain technologie control 0.32.4

gplhost domain technologie control 0.25.2

Vendor Advisories

Ansgar Burchardt discovered several vulnerabilities in DTC, a web control panel for admin and accounting hosting services CVE-2011-0434 The bw_per_mothphp graph contains an SQL injection vulnerability CVE-2011-0435 Insufficient checks in bw_per_monthphp can lead to bandwidth usage information disclosure CVE-2011-0436 After a r ...