CVE-2011-0436

The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mail message, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

Published: 2011-03-07 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2011-0436 is rated Moderate Risk (47.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.85%). Core evidence: EPSS rose +1.07% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2011-0436

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.78% 1.85% +1.07%
2 2025-03-17 0.46% 0.78% +0.33%
3 2023-03-07 0.46%

Full EPSS history (4 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2011-0436

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2011-0436

OS Trackers for CVE-2011-0436

vendor priority summary link
ubuntu low CVE-2011-0436 low priority: Ubuntu including 1 source packages (dtc), 6 status rows across 6 suites (dapper, hardy, karmic, lucid, maverick, upstream): released 5, DNE 1. https://ubuntu.com/security/CVE-2011-0436

Affected software / configurations for CVE-2011-0436

Vendor Product Version Raw CPE
gplhost domain_technologie_control <= 0.32.8 cpe:2.3:a:gplhost:domain_technologie_control:*:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.24.6 cpe:2.3:a:gplhost:domain_technologie_control:0.24.6:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.25.1 cpe:2.3:a:gplhost:domain_technologie_control:0.25.1:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.25.2 cpe:2.3:a:gplhost:domain_technologie_control:0.25.2:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.25.3 cpe:2.3:a:gplhost:domain_technologie_control:0.25.3:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.26.7 cpe:2.3:a:gplhost:domain_technologie_control:0.26.7:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.26.8 cpe:2.3:a:gplhost:domain_technologie_control:0.26.8:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.26.9 cpe:2.3:a:gplhost:domain_technologie_control:0.26.9:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.27.3 cpe:2.3:a:gplhost:domain_technologie_control:0.27.3:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.28.2 cpe:2.3:a:gplhost:domain_technologie_control:0.28.2:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.28.3 cpe:2.3:a:gplhost:domain_technologie_control:0.28.3:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.28.4 cpe:2.3:a:gplhost:domain_technologie_control:0.28.4:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.28.6 cpe:2.3:a:gplhost:domain_technologie_control:0.28.6:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.28.9 cpe:2.3:a:gplhost:domain_technologie_control:0.28.9:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.28.10 cpe:2.3:a:gplhost:domain_technologie_control:0.28.10:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.1 cpe:2.3:a:gplhost:domain_technologie_control:0.29.1:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.6 cpe:2.3:a:gplhost:domain_technologie_control:0.29.6:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.8 cpe:2.3:a:gplhost:domain_technologie_control:0.29.8:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.10 cpe:2.3:a:gplhost:domain_technologie_control:0.29.10:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.14 cpe:2.3:a:gplhost:domain_technologie_control:0.29.14:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.15 cpe:2.3:a:gplhost:domain_technologie_control:0.29.15:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.16 cpe:2.3:a:gplhost:domain_technologie_control:0.29.16:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.29.17 cpe:2.3:a:gplhost:domain_technologie_control:0.29.17:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.30.6 cpe:2.3:a:gplhost:domain_technologie_control:0.30.6:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.30.8 cpe:2.3:a:gplhost:domain_technologie_control:0.30.8:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.30.10 cpe:2.3:a:gplhost:domain_technologie_control:0.30.10:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.30.18 cpe:2.3:a:gplhost:domain_technologie_control:0.30.18:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.30.20 cpe:2.3:a:gplhost:domain_technologie_control:0.30.20:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.32.1 cpe:2.3:a:gplhost:domain_technologie_control:0.32.1:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.32.2 cpe:2.3:a:gplhost:domain_technologie_control:0.32.2:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.32.3 cpe:2.3:a:gplhost:domain_technologie_control:0.32.3:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.32.4 cpe:2.3:a:gplhost:domain_technologie_control:0.32.4:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.32.5 cpe:2.3:a:gplhost:domain_technologie_control:0.32.5:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.32.6 cpe:2.3:a:gplhost:domain_technologie_control:0.32.6:*:*:*:*:*:*:*
gplhost domain_technologie_control 0.32.7 cpe:2.3:a:gplhost:domain_technologie_control:0.32.7:*:*:*:*:*:*:*

References for CVE-2011-0436

cvelogic Threat Intelligence