2.1
CVSSv2

CVE-2011-3198

Published: 21/03/2014 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Domain Technologie Control (DTC) prior to 0.34.1 includes a password in the -b command line argument to htpasswd, which might allow local users to read the password by listing the process and its arguments.

Vulnerable Product Search on Vulmon Subscribe to Product

gplhost domain technologie control 0.29.8

gplhost domain technologie control 0.28.9

gplhost domain technologie control 0.32.1

gplhost domain technologie control 0.25.3

gplhost domain technologie control 0.30.6

gplhost domain technologie control 0.26.9

gplhost domain technologie control 0.29.1

gplhost domain technologie control 0.27.3

gplhost domain technologie control 0.28.4

gplhost domain technologie control

gplhost domain technologie control 0.32.3

gplhost domain technologie control 0.28.10

gplhost domain technologie control 0.25.1

gplhost domain technologie control 0.30.18

gplhost domain technologie control 0.26.8

gplhost domain technologie control 0.28.6

gplhost domain technologie control 0.28.2

gplhost domain technologie control 0.32.2

gplhost domain technologie control 0.29.14

gplhost domain technologie control 0.29.17

gplhost domain technologie control 0.26.7

gplhost domain technologie control 0.29.16

gplhost domain technologie control 0.30.10

gplhost domain technologie control 0.32.6

gplhost domain technologie control 0.29.6

gplhost domain technologie control 0.28.3

gplhost domain technologie control 0.24.6

gplhost domain technologie control 0.32.5

gplhost domain technologie control 0.29.15

gplhost domain technologie control 0.29.10

gplhost domain technologie control 0.30.20

gplhost domain technologie control 0.30.8

gplhost domain technologie control 0.32.7

gplhost domain technologie control 0.32.4

gplhost domain technologie control 0.25.2

Vendor Advisories

Ansgar Burchardt, Mike O'Connor and Philipp Kern discovered multiple vulnerabilities in DTC, a web control panel for admin and accounting hosting services: CVE-2011-3195 A possible shell insertion has been found in the mailing list handling CVE-2011-3196 Unix rights for the apache2conf were set incorrectly (world readable) CVE-2 ...