CVE-2006-2531
- EPSS 4.65%
- Published 22.05.2006 23:10:00
- Last modified 03.04.2025 01:03:51
Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Applicati...
- EPSS 5.78%
- Published 28.02.2006 11:02:00
- Last modified 03.04.2025 01:03:51
NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn p...
CVE-2005-1250
- EPSS 18.05%
- Published 22.06.2005 04:00:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) P...