CVE Vulnerabilities

CVE-2011-0435

Improper Authentication

Published: Mar 07, 2011 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Domain_technologie_control Gplhost * 0.32.8 (including)
Domain_technologie_control Gplhost 0.24.6 (including) 0.24.6 (including)
Domain_technologie_control Gplhost 0.25.1 (including) 0.25.1 (including)
Domain_technologie_control Gplhost 0.25.2 (including) 0.25.2 (including)
Domain_technologie_control Gplhost 0.25.3 (including) 0.25.3 (including)
Domain_technologie_control Gplhost 0.26.7 (including) 0.26.7 (including)
Domain_technologie_control Gplhost 0.26.8 (including) 0.26.8 (including)
Domain_technologie_control Gplhost 0.26.9 (including) 0.26.9 (including)
Domain_technologie_control Gplhost 0.27.3 (including) 0.27.3 (including)
Domain_technologie_control Gplhost 0.28.2 (including) 0.28.2 (including)
Domain_technologie_control Gplhost 0.28.3 (including) 0.28.3 (including)
Domain_technologie_control Gplhost 0.28.4 (including) 0.28.4 (including)
Domain_technologie_control Gplhost 0.28.6 (including) 0.28.6 (including)
Domain_technologie_control Gplhost 0.28.9 (including) 0.28.9 (including)
Domain_technologie_control Gplhost 0.28.10 (including) 0.28.10 (including)
Domain_technologie_control Gplhost 0.29.1 (including) 0.29.1 (including)
Domain_technologie_control Gplhost 0.29.6 (including) 0.29.6 (including)
Domain_technologie_control Gplhost 0.29.8 (including) 0.29.8 (including)
Domain_technologie_control Gplhost 0.29.10 (including) 0.29.10 (including)
Domain_technologie_control Gplhost 0.29.14 (including) 0.29.14 (including)
Domain_technologie_control Gplhost 0.29.15 (including) 0.29.15 (including)
Domain_technologie_control Gplhost 0.29.16 (including) 0.29.16 (including)
Domain_technologie_control Gplhost 0.29.17 (including) 0.29.17 (including)
Domain_technologie_control Gplhost 0.30.6 (including) 0.30.6 (including)
Domain_technologie_control Gplhost 0.30.8 (including) 0.30.8 (including)
Domain_technologie_control Gplhost 0.30.10 (including) 0.30.10 (including)
Domain_technologie_control Gplhost 0.30.18 (including) 0.30.18 (including)
Domain_technologie_control Gplhost 0.30.20 (including) 0.30.20 (including)
Domain_technologie_control Gplhost 0.32.1 (including) 0.32.1 (including)
Domain_technologie_control Gplhost 0.32.2 (including) 0.32.2 (including)
Domain_technologie_control Gplhost 0.32.3 (including) 0.32.3 (including)
Domain_technologie_control Gplhost 0.32.4 (including) 0.32.4 (including)
Domain_technologie_control Gplhost 0.32.5 (including) 0.32.5 (including)
Domain_technologie_control Gplhost 0.32.6 (including) 0.32.6 (including)
Domain_technologie_control Gplhost 0.32.7 (including) 0.32.7 (including)

Potential Mitigations

References