FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-07-07T00:00:00

Updated: 2024-08-07T18:30:33.542Z

Reserved: 2006-07-06T00:00:00

Link: CVE-2006-3425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-07-07T00:05:00.000

Modified: 2018-10-18T16:47:27.173

Link: CVE-2006-3425

cve-icon Redhat

No data.