CVE-2006-1774: High severity HP CompaqHTTPServer vulnerability
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1774?
The severity of CVE-2006-1774 is classified as medium risk due to authentication bypass allowing remote attackers access.
How do I fix CVE-2006-1774?
To fix CVE-2006-1774, enable the 'Trust by Certificates' feature in the HP System Management Homepage configuration.
Which software is affected by CVE-2006-1774?
CVE-2006-1774 affects HP System Management Homepage version 2.1.3.132 running on CompaqHTTPServer version 9.9.
Can CVE-2006-1774 be exploited remotely?
Yes, CVE-2006-1774 can be exploited remotely through a crafted URL, leading to unauthorized access.
Is there a patch available for CVE-2006-1774?
HP has not released a specific patch for CVE-2006-1774, but it is recommended to apply best practices such as enabling SSL and certificates.