|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> VHCS check_login Authentication Bypass Vulnerability Vulnerability Assessment Details
|
VHCS check_login Authentication Bypass Vulnerability |
||
Tries to access a restricted script using VHCS Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a PHP application that is prone to an authentication bypass vulnerability. Description : The remote host is running VHCS, a control panel for hosting providers. The GUI portion of the version of VHCS installed on the remote host does not halt script execution if 'check_login()' fails. A possible hacker can leverage this flaw to bypass authentication and access VHCS application scripts that would otherwise be restricted. See also : http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt http://archives.neohapsis.com/archives/bugtraq/2006-02/0166.html http://www.rs-labs.com/exploitsntools/rs_vhcs_simple_poc.html http://vhcs.net/new/modules/news/article.php?storyid=25 Solution : Apply Security Patch 2006-02-09 referenced in the project advisory above. Network Security Threat Level: Critical / CVSS Base Score : 10.0 (AV:R/AC:L/Au:NR/C:C/I:C/A:C/B:N) Networks Security ID: 16600 Vulnerability Assessment Copyright: This script is Copyright (C) 2006 Tenable Network Security |
||
Cables, Connectors |
LSI 9305-16i SATA SAS 12Gbs RAID Controller PCIe 3.0 x8 IT-Mode 4* 8643 SATA
$229.99
IBM LSI SAS9220-8i M1015 46M0861 SAS/SATA PCI-e RAID Controller Both brackets
$139.00
XDHXT DELL PERC H710P 6Gbps 1GB PCI RAID CONTROLLER 0XDHXT
$59.00
HPE 869102-001 Smart Array E208i-a SR Gen10 Storage Controller RAID SP: 871039
$116.99
Inspur LSI 9300-8i Raid Card 12Gbps HBA HDD Controller High Profile IT MODE
$15.98
LSI MegaRAID 9361-8i 12Gb PCIe 8-Port SAS/SATA RAID 1Gb w/BBU/CacheVault/License
$39.95
ORICO Multi Bay RAID Hard Drive Enclosure USB 3.0/ Type-C For 2.5/3.5'' HDD SSDs
$87.99
Dell PowerEdge RAID Controller HBA330 12Gbs PCIe 3.0 SAS SATA J7TNV Low Profile
$29.00
4 Bay RAID External Hard Drive Enclosure for 2.5/3.5" SATA HDD/SSD
$79.99
G TECHNOLOGY G RAID 0G04228 2-Bay Thunderbolt 2 RAID Array W/Power Supply
$99.99
|
||
No Discussions have been posted on this vulnerability. |