Vulnerabilities > CVE-2006-2531 - Unspecified vulnerability in Ipswitch Whatsup Professional2006
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Ipswitch WhatsUp Professional 2006 Authentication Bypass Vulnerability. CVE-2006-2531. Remote exploit for hardware platform |
id | EDB-ID:27891 |
last seen | 2016-02-03 |
modified | 2006-05-17 |
published | 2006-05-17 |
reporter | Kenneth F. Belva |
source | https://www.exploit-db.com/download/27891/ |
title | Ipswitch WhatsUp Professional 2006 - Authentication Bypass Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | IPSWITCH_WHATSUP_AUTH_BYPASS.NASL |
description | The remote host is running Ipswitch WhatsUp Professional, which is used to monitor states of applications, services and hosts. The version of WhatsUp Professional installed on the remote host allows an attacker to bypass authentication with a specially crafted request. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21572 |
published | 2006-05-18 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21572 |
title | Ipswitch WhatsUp Professional Crafted Header Authentication Bypass |
References
- http://www.ftusecurity.com/pub/whatsup.public.pdf
- http://www.securityfocus.com/bid/18019
- http://www.vupen.com/english/advisories/2006/1849
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26529
- http://www.securityfocus.com/archive/1/434447/100/0/threaded
- http://www.securityfocus.com/archive/1/434247/100/0/threaded