CVE-2011-0435

Gplhost Domain Technologie Control < 0.32.8 - Authentication Bypass

Title source: rule

Description

Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.

Scores

EPSS 0.0083
EPSS Percentile 74.4%

Classification

CWE
CWE-287
Status draft

Affected Products (35)

gplhost/domain_technologie_control < 0.32.8
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
gplhost/domain_technologie_control
... and 20 more

Timeline

Published Mar 07, 2011
Tracked Since Feb 18, 2026