CVE-2006-2531
CVE-2006-2531
Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/27891unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://exchange.xforce.ibmcloud.com/vulnerabilities/26529http://www.ftusecurity.com/pub/whatsup.public.pdfhttp://www.securityfocus.com/archive/1/434247/100/0/threadedhttp://www.securityfocus.com/archive/1/434447/100/0/threadedhttp://www.securityfocus.com/bid/18019http://www.vupen.com/english/advisories/2006/1849