Ipswitch WhatsUp Professional 2006 - Authentication Bypass
Author: Kenneth F. Belva
type: remote
platform: hardware
port:
date_added: 2006-05-17
date_updated: 2013-08-27
verified: 1
codes: CVE-2006-2531;OSVDB-25839
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/18019/info
Ipswitch WhatsUp Professional 2006 is susceptible to a remote authentication-bypass vulnerability.
This issue allows remote attackers to gain administrative access to the web-based administrative interface of the application. This will aid them in further network attacks.
The HTTP requests containing the following header information are sufficient to demonstrate this issue:
User-Agent: Ipswitch/1.0
User-Application: NmConsole