CVE-2006-3425

F

astPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lumension:patchlink_update_server:6.1:*:*:*:*:*:*:*
cpe:2.3:a:lumension:patchlink_update_server:6.2.0.181:*:*:*:*:*:*:*
cpe:2.3:a:lumension:patchlink_update_server:6.2.0.189:*:*:*:*:*:*:*
cpe:2.3:a:novell:zenworks:*:sr1:*:*:*:*:*:*

History

21 Nov 2024, 00:13

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047495.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047495.html -
References () http://secunia.com/advisories/20876 - Patch, Vendor Advisory () http://secunia.com/advisories/20876 - Patch, Vendor Advisory
References () http://secunia.com/advisories/20878 - Patch, Vendor Advisory () http://secunia.com/advisories/20878 - Patch, Vendor Advisory
References () http://securityreason.com/securityalert/1200 - () http://securityreason.com/securityalert/1200 -
References () http://securitytracker.com/id?1016405 - Patch () http://securitytracker.com/id?1016405 - Patch
References () http://www.securityfocus.com/archive/1/438710/100/0/threaded - () http://www.securityfocus.com/archive/1/438710/100/0/threaded -
References () http://www.securityfocus.com/bid/18723 - () http://www.securityfocus.com/bid/18723 -
References () http://www.vupen.com/english/advisories/2006/2595 - () http://www.vupen.com/english/advisories/2006/2595 -
References () http://www.vupen.com/english/advisories/2006/2596 - () http://www.vupen.com/english/advisories/2006/2596 -

Information

Published : 2006-07-07 00:05

Updated : 2025-04-03 01:03


NVD link : CVE-2006-3425

Mitre link : CVE-2006-3425

CVE.ORG link : CVE-2006-3425


JSON object : View