Vulnerability Description
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Compaqhttpserver | 9.9 |
| Hp | System Management Homepage | 2.1.3.132 |
References
- http://securitytracker.com/id?1015901
- http://src.telindus.com/articles/hpsm_vulnerability.html
- http://www.securityfocus.com/archive/1/430688/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25761
- http://securitytracker.com/id?1015901
- http://src.telindus.com/articles/hpsm_vulnerability.html
- http://www.securityfocus.com/archive/1/430688/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25761
FAQ
What is CVE-2006-1774?
CVE-2006-1774 is a vulnerability with a CVSS score of 7.5 (HIGH). HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass...
How severe is CVE-2006-1774?
CVE-2006-1774 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1774?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Compaqhttpserver, Hp System Management Homepage.