Lucene search

K
cveMitreCVE-2006-0232
HistoryApr 25, 2006 - 1:02 a.m.

CVE-2006-0232

2006-04-2501:02:00
mitre
web.nvd.nist.gov
30
symantec
scan engine
cve-2006-0232
access control
vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.046

Percentile

92.6%

Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.

Affected configurations

Nvd
Node
symantecantivirus_scan_engineMatch5.0.0.24
VendorProductVersionCPE
symantecantivirus_scan_engine5.0.0.24cpe:2.3:a:symantec:antivirus_scan_engine:5.0.0.24:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.046

Percentile

92.6%