7.5

CVE-2006-5932

Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KahuaKahua Version0.1
KahuaKahua Version0.2
KahuaKahua Version0.3
KahuaKahua Version0.4
KahuaKahua Version0.5
KahuaKahua Version0.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.66% 0.736
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/22785
Patch
Vendor Advisory
http://www.kahua.org/cgi-bin/kahua.fcgi/kahua-web/show/KSA/KSA2006-001
Patch
Vendor Advisory
http://www.securityfocus.com/bid/21074
http://www.timedia.co.jp/news/2467470581
Patch
Vendor Advisory
http://www.vupen.com/english/advisories/2006/4486
https://exchange.xforce.ibmcloud.com/vulnerabilities/30206