128 lines
4.0 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2006-5932",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-11-16T00:07:00.000",
"lastModified": "2017-07-20T01:34:05.103",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts."
},
{
"lang": "es",
"value": "Kahua anterior a 7.0, cuando funcionan m\u00faltiples aplicaciones bajo un solo supervisor, se consigue acceso de aplicaci\u00f3n sobre la base de un nombre de usuario en vez de un nombre de usuario y un nombre de base de datos, lo cual permite a un usuario remoto validado obtener acceso no autorizado si deiferentes bases de datos asignadas al nombre de usuario son diferentes que las cuentas de usuario."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:kahua:kahua:0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "DB21AFE7-3250-4F0F-845F-76CE29906954"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:kahua:kahua:0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "49174D83-6F6C-42E4-935A-D686E1CD6E08"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:kahua:kahua:0.3:*:*:*:*:*:*:*",
"matchCriteriaId": "CAA7BEA1-DC09-4C4B-BD39-5198AB8B4CF4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:kahua:kahua:0.4:*:*:*:*:*:*:*",
"matchCriteriaId": "C844AE56-8A67-4736-A467-B4CFC464077B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:kahua:kahua:0.5:*:*:*:*:*:*:*",
"matchCriteriaId": "3546DC24-2757-478A-A7AF-95ACD0D7A455"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:kahua:kahua:0.6:*:*:*:*:*:*:*",
"matchCriteriaId": "C073320A-C02A-4A50-B621-20FBE33C727A"
}
]
}
]
}
],
"references": [
{
"url": "http://www.kahua.org/cgi-bin/kahua.fcgi/kahua-web/show/KSA/KSA2006-001",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/21074",
"source": "cve@mitre.org"
},
{
"url": "http://www.timedia.co.jp/news/2467470581",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/4486",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30206",
"source": "cve@mitre.org"
}
]
}