First published: Thu Apr 13 2006(Updated: )
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Compaqhttpserver | =9.9 | |
HP System Management Homepage | =2.1.3.132 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-1774 is classified as medium risk due to authentication bypass allowing remote attackers access.
To fix CVE-2006-1774, enable the 'Trust by Certificates' feature in the HP System Management Homepage configuration.
CVE-2006-1774 affects HP System Management Homepage version 2.1.3.132 running on CompaqHTTPServer version 9.9.
Yes, CVE-2006-1774 can be exploited remotely through a crafted URL, leading to unauthorized access.
HP has not released a specific patch for CVE-2006-1774, but it is recommended to apply best practices such as enabling SSL and certificates.