Vulnerability CVE-2006-6246


Published: 2006-12-04   Modified: 2012-02-12

Description:
Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Photo organizer -> Photo organizer 

 References:
http://bugs.shaftnet.org/task/113
http://po.shaftnet.org/po_stable_changelog
http://www.securityfocus.com/bid/21351
http://www.vupen.com/english/advisories/2006/4766
https://exchange.xforce.ibmcloud.com/vulnerabilities/30577

Copyright 2024, cxsecurity.com

 

Back to Top