Vulnerabilities > CVE-2006-0686 - Input Validation And Access Validation vulnerability in Virtual Hosting Control System

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
virtual-hosting-control-system
critical

Summary

add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.

Vulnerable Configurations

Part Description Count
Application
Virtual_Hosting_Control_System
1