VulnerabilityModified
CVE-2006-2353
NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters.
MEDIUM 5.0EPSS 3.13%
Does this matter?
Lower severity and a low EPSS score (3.13%). Track it; it rarely justifies an emergency change on its own.
Description
NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.13% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ipswitch/whatsup professional
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20075Vendor Advisory
- http://securityreason.com/securityalert/897
- http://www.osvdb.org/25473
- http://www.securityfocus.com/archive/1/433808Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1787Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26502
- http://secunia.com/advisories/20075Vendor Advisory
- http://securityreason.com/securityalert/897
- http://www.osvdb.org/25473
- http://www.securityfocus.com/archive/1/433808Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1787Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26502
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.