Back to Database
Status published
Medium
CVE-2010-0550
admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly...
Vulnerability Description
admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly enforce HTTP Digest Authentication, which allows remote authenticated users to use HTTP Basic Authentication, bypassing intended server policy.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-0550
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/509199/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55976
- http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication
- http://osvdb.org/62013
- http://secunia.com/advisories/38323
More from geopp
View All →CVE-2010-0554
The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier...
High
7.5
CVE-2010-0553
Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to...
Medium
6.5
CVE-2010-0552
Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause...
High
7.5
CVE-2010-0551
HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows...
Medium
5
Affected Vendor
geopp
View all reports →Affected Software
geo\+\+ gncaster
Vulnerable Versions:
0, 1.4.0.0
Timeline
Official Publish:
February 4th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.