HIGH · 10.0

CVE-2006-0685

The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.

Vulnerability Description

The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Virtual Hosting Control SystemVirtual Hosting Control System<= 2.4.7.1

References

FAQ

What is CVE-2006-0685?

CVE-2006-0685 is a vulnerability with a CVSS score of 10.0 (HIGH). The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.

How severe is CVE-2006-0685?

CVE-2006-0685 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0685?

Check the references section above for vendor advisories and patch information. Affected products include: Virtual Hosting Control System Virtual Hosting Control System.