CVE-2011-0435

Domain Technologie Control < 0.32.9 - Unauthenticated Sensitive Information Exposure via Bandwidth Endpoints

Title source: llm
STIX 2.1

Description

Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43523
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0556
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2179
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65896
Patch mailing-list x_refsource_mlist
http://www.gplhost.sg/lists/dtcannounce/msg00025.html

Scores

EPSS 0.0197
EPSS Percentile 78.0%

Details

CWE
CWE-287
Status published
Products (35)
gplhost/domain_technologie_control 0.24.6
gplhost/domain_technologie_control 0.25.1
gplhost/domain_technologie_control 0.25.2
gplhost/domain_technologie_control 0.25.3
gplhost/domain_technologie_control 0.26.7
gplhost/domain_technologie_control 0.26.8
gplhost/domain_technologie_control 0.26.9
gplhost/domain_technologie_control 0.27.3
gplhost/domain_technologie_control 0.28.2
gplhost/domain_technologie_control 0.28.3
... and 25 more
Published Mar 07, 2011
Tracked Since Feb 18, 2026