Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ipswitch WhatsUp Professional 认证绕过漏洞
Vulnerability Description
Whatsup Professional软件是Ipswitch公司开发的监视TCP/IP、NetBEUI和IPX网络状态的工具。 What's Up Professional 2006存在绕过认证漏洞,攻击者就可以绕过认证机制无需凭据便可登录。攻击者可以通过发送有特制首部的HTTP请求诱骗应用程序相信请求来自控制台,而控制台是可信任的。
CVSS Information
N/A
Vulnerability Type
N/A