Vulnerabilities > CVE-2006-0684 - Unspecified vulnerability in Virtual Hosting Control System Virtual Hosting Control System
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN virtual-hosting-control-system
exploit available
Summary
change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Virtual Hosting Control System 2.2/2.4 change_password.php Current Password Weakness. CVE-2006-0684. Webapps exploit for php platform |
id | EDB-ID:27204 |
last seen | 2016-02-03 |
modified | 2006-02-13 |
published | 2006-02-13 |
reporter | Roman Medina-Heigl Hernandez |
source | https://www.exploit-db.com/download/27204/ |
title | Virtual Hosting Control System 2.2/2.4 change_password.php Current Password Weakness |