CVE-2006-6973

UnknownEPSS 1.34%

Last modified

CVE-2006-6973 is a vulnerability of currently unknown severity. Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.

Description

Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/.

Metrics

EPSS Probability
1.34%

67.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Headstart SolutionsDeskproAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-6973?
Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/.
How severe is CVE-2006-6973?
Severity scoring for CVE-2006-6973 is pending analysis. The EPSS model estimates a 1.34% probability of exploitation in the next 30 days.
How do I fix CVE-2006-6973?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-6973?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST