Ipswitch

Whatsup Professional

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.9%
  • Veröffentlicht 15.05.2006 10:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) Nm...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 15.05.2006 10:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmCon...

  • EPSS 0.13%
  • Veröffentlicht 15.05.2006 10:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 15.05.2006 10:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information i...

Exploit
  • EPSS 1.4%
  • Veröffentlicht 15.05.2006 10:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely fr...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 15.05.2006 10:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter.

  • EPSS 0.25%
  • Veröffentlicht 15.05.2006 10:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp.