7.5
CVE-2006-5932
- EPSS 1.66%
- Veröffentlicht 16.11.2006 00:07:00
- Zuletzt bearbeitet 16.06.2026 22:32:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.66% | 0.736 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/22785
http://www.kahua.org/cgi-bin/kahua.fcgi/kahua-web/show/KSA/KSA2006-001
http://www.securityfocus.com/bid/21074
http://www.timedia.co.jp/news/2467470581
http://www.vupen.com/english/advisories/2006/4486
https://exchange.xforce.ibmcloud.com/vulnerabilities/30206