CVE-2006-0911: Medium severity Ipswitch WhatsUp vulnerability
NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "[" (closing bracket) characters, as demonstrated by "&btnLogIn=[Log&In]=&" or "&b;tnLogIn=[Log&In]=&" in the URL. NOTE: due to the lack of diagnosis by the original researcher, the precise nature of the vulnerability is unclear.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0911?
CVE-2006-0911 is considered a high severity vulnerability due to its capability to cause denial of service through CPU consumption.
How do I fix CVE-2006-0911?
To fix CVE-2006-0911, ensure that you apply the latest patches or updates for Ipswitch WhatsUp Professional 2006.
What systems are affected by CVE-2006-0911?
CVE-2006-0911 affects Ipswitch WhatsUp Professional 2006.
What type of attack does CVE-2006-0911 facilitate?
CVE-2006-0911 facilitates denial of service attacks through crafted requests targeting specific parameters.
Is there a known exploit for CVE-2006-0911?
Yes, CVE-2006-0911 has known exploits that demonstrate how to trigger CPU consumption leading to denial of service.