Vulnerabilities > CVE-2006-0911 - Resource Management Errors vulnerability in Ipswitch Whatsup Professional2006

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
ipswitch
CWE-399
exploit available

Summary

NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "[" (closing bracket) characters, as demonstrated by "&btnLogIn=[Log&In]=&" or "&b;tnLogIn=[Log&In]=&" in the URL. NOTE: due to the lack of diagnosis by the original researcher, the precise nature of the vulnerability is unclear.

Vulnerable Configurations

Part Description Count
Application
Ipswitch
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionIpswitch WhatsUp Professional 2006 Remote Denial Of Service Vulnerability. CVE-2006-0911. Dos exploit for asp platform
idEDB-ID:27258
last seen2016-02-03
modified2006-02-22
published2006-02-22
reporterJosh Zlatin-Amishav
sourcehttps://www.exploit-db.com/download/27258/
titleIpswitch WhatsUp Professional 2006 - Remote Denial of Service Vulnerability