CVE-2011-0435
Domain Technologie Control < 0.32.9 - Unauthenticated Sensitive Information Exposure via Bandwidth Endpoints
Title source: llmDescription
Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.
References (9)
Core 9
Core References
Various Sources x_refsource_confirm
http://packages.debian.org/changelogs/pool/main/d/dtc/dtc_0.29.17-1+lenny1/changelog
Various Sources x_refsource_confirm
http://git.gplhost.com/gitweb/?p=dtc.git%3Ba=commit%3Bh=e94e8b9cc354bfcaeb284d5331b815256bb46162
Various Sources x_refsource_confirm
http://packages.debian.org/changelogs/pool/main/d/dtc/dtc_0.32.10-1/changelog
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43523
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0556
Various Sources x_refsource_confirm
http://git.gplhost.com/gitweb/?p=dtc.git%3Ba=commit%3Bh=89da9c519b04cda1b23e6290d2b0a6cea1bae31e
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2179
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65896
Patch mailing-list
x_refsource_mlist
http://www.gplhost.sg/lists/dtcannounce/msg00025.html
Scores
EPSS
0.0197
EPSS Percentile
78.0%
Details
CWE
CWE-287
Status
published
Products (35)
gplhost/domain_technologie_control
0.24.6
gplhost/domain_technologie_control
0.25.1
gplhost/domain_technologie_control
0.25.2
gplhost/domain_technologie_control
0.25.3
gplhost/domain_technologie_control
0.26.7
gplhost/domain_technologie_control
0.26.8
gplhost/domain_technologie_control
0.26.9
gplhost/domain_technologie_control
0.27.3
gplhost/domain_technologie_control
0.28.2
gplhost/domain_technologie_control
0.28.3
... and 25 more
Published
Mar 07, 2011
Tracked Since
Feb 18, 2026