CVE-2006-6973
Last modified
CVE-2006-6973 is a vulnerability of currently unknown severity. Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Headstart Solutions | Deskpro | All versions |
References
- http://www.zion-security.com/text/Mul_Vulnerability_DeskPro.txtExploit, Vendor Advisory
- http://www.zion-security.com/text/Mul_Vulnerability_DeskPro.txtExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6973?
How severe is CVE-2006-6973?
How do I fix CVE-2006-6973?
Are you affected by CVE-2006-6973?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
