[] NeoSense

Ipswitch WhatsUp Professional 2006 - Authentication Bypass

Author: Kenneth F. Belva
type: remote
platform: hardware
port: 
date_added: 2006-05-17 
date_updated: 2013-08-27 
verified: 1 
codes: CVE-2006-2531;OSVDB-25839 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/18019/info

Ipswitch WhatsUp Professional 2006 is susceptible to a remote authentication-bypass vulnerability.

This issue allows remote attackers to gain administrative access to the web-based administrative interface of the application. This will aid them in further network attacks.

The HTTP requests containing the following header information are sufficient to demonstrate this issue:

User-Agent: Ipswitch/1.0
User-Application: NmConsole