Vulnerability CVE-2006-5932


Published: 2006-11-15   Modified: 2012-02-12

Description:
Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Kahua -> Kahua 

 References:
http://www.timedia.co.jp/news/2467470581
http://www.kahua.org/cgi-bin/kahua.fcgi/kahua-web/show/KSA/KSA2006-001
http://secunia.com/advisories/22785
http://xforce.iss.net/xforce/xfdb/30206
http://www.vupen.com/english/advisories/2006/4486
http://www.securityfocus.com/bid/21074

Copyright 2024, cxsecurity.com

 

Back to Top