Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2005-1932 | First vendor Publication | 2005-07-05 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.1 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1932 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
17136 | Lpanel diagnose.php Arbitrary Domain DNS Setting Reset DoS lpanel contains a flaw that may allow a remote denial of service. The issue is triggered when a user uses diagnose.php to reset the DNS of an arbitrary domain managed by lpanel, and will result in loss of availability for the domain. |
17135 | Lpanel viewreceipt.php Arbitrary Invoice Access Lpanel contains a flaw that may allow a remote denial of service. The issue is triggered when a logged in user modifies the DNS settings for another domain managed by Lpanel. It could result in loss of availability for the Domain. |
17134 | Lpanel domains.php Arbitrary Domain Modification |
17133 | Lpanel view_ticket.php Arbitrary Ticket Manipulation |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:03 |
|
2024-11-28 12:07:11 |
|
2021-05-04 12:03:01 |
|
2021-04-22 01:03:16 |
|
2020-05-23 00:16:38 |
|
2016-04-26 13:36:21 |
|
2013-05-11 11:27:32 |
|