CVE-2006-0684

Virtual Hosting Control System <2.4.7.1 - Info Disclosure

Title source: llm

Description

change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Roman Medina-Heigl Hernandez · htmlwebappsphp
https://www.exploit-db.com/exploits/27204

Scores

EPSS 0.0914
EPSS Percentile 92.7%

Details

Status published
Products (1)
virtual_hosting_control_system/virtual_hosting_control_system < 2.4.7.1
Published Feb 15, 2006
Tracked Since Feb 18, 2026