Lucene search

K
cve[email protected]CVE-2006-4782
HistorySep 14, 2006 - 10:07 a.m.

CVE-2006-4782

2006-09-1410:07:00
web.nvd.nist.gov
26
webspell
cve-2006-4782
security
authentication bypass
database vulnerability

5.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:C/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.6%

src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php.

Affected configurations

NVD
Node
webspellwebspellRange4.01.01
OR
webspellwebspellMatch4.0
OR
webspellwebspellMatch4.1
OR
webspellwebspellMatch4.1.1

5.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:C/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.6%

Related for CVE-2006-4782