4.6

CVE-2006-5965

PassGo SSO Plus 2.1.0.32, and probably earlier versions, uses insecure permissions (Everyone/Full Control) for the PassGo Technologies directory, which allows local users to gain privileges by modifying critical programs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PassgoSso Plus Version2.1.0.32
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.252
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/22301
Vendor Advisory
http://secunia.com/secunia_research/2006-68/advisory
Vendor Advisory
http://securitytracker.com/id?1017272
http://www.securityfocus.com/archive/1/452325/100/0/threaded
http://www.securityfocus.com/bid/21244
http://www.vupen.com/english/advisories/2006/4660
https://exchange.xforce.ibmcloud.com/vulnerabilities/30475