CVE Vulnerabilities

CVE-2006-0911

Published: Feb 28, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) In] and (2) b;tnLogIn parameters, or (3) malformed btnLogIn parameters, possibly involving missing [ (open bracket) or [ (closing bracket) characters, as demonstrated by &btnLogIn=[Log&In]=& or &b;tnLogIn=[Log&In]=& in the URL. NOTE: due to the lack of diagnosis by the original researcher, the precise nature of the vulnerability is unclear.

Affected Software

Name Vendor Start Version End Version
Whatsup Ipswitch professional_2006 (including) professional_2006 (including)

References