Lucene search

K
freebsdFreeBSD879B0242-C5B6-11E0-ABD1-0017F22D6707
HistoryMar 02, 2011 - 12:00 a.m.

dtc -- multiple vulnerabilities

2011-03-0200:00:00
vuxml.freebsd.org
8

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.007

Percentile

80.4%

Ansgar Burchardt reports:

Ansgar Burchardt discovered several vulnerabilities in DTC, a
web control panel for admin and accounting hosting services:
The bw_per_moth.php graph contains an SQL injection
vulnerability; insufficient checks in bw_per_month.php can lead
to bandwidth usage information disclosure; after a registration,
passwords are sent in cleartext email messages and Authenticated
users could delete accounts using an obsolete interface which
was incorrectly included in the package.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchdtc< 0.32.9UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.007

Percentile

80.4%

Related for 879B0242-C5B6-11E0-ABD1-0017F22D6707