5

CVE-2011-0435

Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GplhostDomain Technologie Control Version <= 0.32.8
GplhostDomain Technologie Control Version0.28.10
GplhostDomain Technologie Control Version0.29.10
GplhostDomain Technologie Control Version0.29.14
GplhostDomain Technologie Control Version0.29.15
GplhostDomain Technologie Control Version0.29.16
GplhostDomain Technologie Control Version0.29.17
GplhostDomain Technologie Control Version0.30.10
GplhostDomain Technologie Control Version0.30.18
GplhostDomain Technologie Control Version0.30.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.97% 0.779
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://git.gplhost.com/gitweb/?p=dtc.git%3Ba=commit%3Bh=89da9c519b04cda1b23e6290d2b0a6cea1bae31e
http://git.gplhost.com/gitweb/?p=dtc.git%3Ba=commit%3Bh=e94e8b9cc354bfcaeb284d5331b815256bb46162
http://packages.debian.org/changelogs/pool/main/d/dtc/dtc_0.29.17-1+lenny1/changelog
http://packages.debian.org/changelogs/pool/main/d/dtc/dtc_0.32.10-1/changelog
http://secunia.com/advisories/43523
Vendor Advisory
http://www.debian.org/security/2011/dsa-2179
http://www.gplhost.sg/lists/dtcannounce/msg00025.html
Patch
http://www.vupen.com/english/advisories/2011/0556
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/65896