| Vulnerability Name: | CVE-2006-3425 (CCN-27546) | ||||||||
| Assigned: | 2006-06-29 | ||||||||
| Published: | 2006-06-29 | ||||||||
| Updated: | 2018-10-18 | ||||||||
| Summary: | FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: Full-Disclosure Mailing List, Wed Jun 28 2006 - 23:10:57 CDT Multiple Vulnerabilities in PatchLink Update Server 6 Source: MITRE Type: CNA CVE-2006-3425 Source: FULLDISC Type: UNKNOWN 20060629 Multiple Vulnerabilities in PatchLink Update Server 6 Source: CCN Type: SA20876 PatchLink Update Server Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 20876 Source: CCN Type: SA20878 Novell ZENworks Patch Management Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 20878 Source: SREASON Type: UNKNOWN 1200 Source: CCN Type: SECTRACK ID: 1016405 PatchLink Update Bugs Let Remote Users Inject SQL Commands, Modify the Configuration, and Create or Overwrite Files Source: SECTRACK Type: Patch 1016405 Source: CCN Type: OSVDB ID: 26926 PatchLink Update Server (PLUS) proxyreg.asp Unauthenticated PDP Server Manipulation Source: CCN Type: PatchLink Web site PatchLink : PatchLink Update Overview Source: BUGTRAQ Type: UNKNOWN 20060629 Multiple Vulnerabilities in PatchLink Update Server 6 Source: BID Type: UNKNOWN 18723 Source: CCN Type: BID-18723 PatchLink Update Server Proxyreg.ASP Authentication Bypass Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2595 Source: VUPEN Type: UNKNOWN ADV-2006-2596 Source: XF Type: UNKNOWN patchlink-proxyreg-authentication-bypass(27546) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||