peter bassill · operator
$ cve CVE-2006-0685 JSON

CVE-2006-0685 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS5.23% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2006-02-15
Last modified2026-06-16

Affected (1)

VendorProduct
virtual hosting control systemvirtual hosting control system

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD