Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-3425

Опубликовано: 07 июл. 2006
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:lumension:patchlink_update_server:6.1:*:*:*:*:*:*:*
cpe:2.3:a:lumension:patchlink_update_server:6.2.0.181:*:*:*:*:*:*:*
cpe:2.3:a:lumension:patchlink_update_server:6.2.0.189:*:*:*:*:*:*:*
cpe:2.3:a:novell:zenworks:*:sr1:*:*:*:*:*:*
Версия до 6.2 (включая)

EPSS

Процентиль: 87%
0.03572
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.

EPSS

Процентиль: 87%
0.03572
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other