Lucene search

K
nvd[email protected]NVD:CVE-2006-4244
HistoryAug 31, 2006 - 1:04 a.m.

CVE-2006-4244

2006-08-3101:04:00
CWE-287
web.nvd.nist.gov

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.034

Percentile

91.5%

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

Affected configurations

NVD
Node
sql-ledgersql-ledgerMatch2.4.4
OR
sql-ledgersql-ledgerMatch2.4.5
OR
sql-ledgersql-ledgerMatch2.4.6
OR
sql-ledgersql-ledgerMatch2.4.7
OR
sql-ledgersql-ledgerMatch2.4.8
OR
sql-ledgersql-ledgerMatch2.4.9
OR
sql-ledgersql-ledgerMatch2.4.10
OR
sql-ledgersql-ledgerMatch2.4.11
OR
sql-ledgersql-ledgerMatch2.4.12
OR
sql-ledgersql-ledgerMatch2.4.13
OR
sql-ledgersql-ledgerMatch2.4.14
OR
sql-ledgersql-ledgerMatch2.4.15
OR
sql-ledgersql-ledgerMatch2.4.16
OR
sql-ledgersql-ledgerMatch2.6.0
OR
sql-ledgersql-ledgerMatch2.6.1
OR
sql-ledgersql-ledgerMatch2.6.2
OR
sql-ledgersql-ledgerMatch2.6.3
OR
sql-ledgersql-ledgerMatch2.6.4
OR
sql-ledgersql-ledgerMatch2.6.5
OR
sql-ledgersql-ledgerMatch2.6.6
OR
sql-ledgersql-ledgerMatch2.6.7
OR
sql-ledgersql-ledgerMatch2.6.8
OR
sql-ledgersql-ledgerMatch2.6.9
OR
sql-ledgersql-ledgerMatch2.6.10
OR
sql-ledgersql-ledgerMatch2.6.11
OR
sql-ledgersql-ledgerMatch2.6.12
OR
sql-ledgersql-ledgerMatch2.6.13
OR
sql-ledgersql-ledgerMatch2.6.14
OR
sql-ledgersql-ledgerMatch2.6.15
OR
sql-ledgersql-ledgerMatch2.6.16
OR
sql-ledgersql-ledgerMatch2.6.17
OR
sql-ledgersql-ledgerMatch2.6.18
OR
sql-ledgersql-ledgerMatch2.6.19
OR
sql-ledgersql-ledgerMatch2.6.20
OR
sql-ledgersql-ledgerMatch2.6.21
OR
sql-ledgersql-ledgerMatch2.6.22
OR
sql-ledgersql-ledgerMatch2.6.23
OR
sql-ledgersql-ledgerMatch2.6.24
OR
sql-ledgersql-ledgerMatch2.6.25
OR
sql-ledgersql-ledgerMatch2.6.26
OR
sql-ledgersql-ledgerMatch2.6.27
OR
sql-ledgersql-ledgerMatch2.8.0
OR
sql-ledgersql-ledgerMatch2.8.1
OR
sql-ledgersql-ledgerMatch2.8.2
OR
sql-ledgersql-ledgerMatch2.8.3
OR
sql-ledgersql-ledgerMatch2.8.4
OR
sql-ledgersql-ledgerMatch2.8.5
OR
sql-ledgersql-ledgerMatch2.8.6
OR
sql-ledgersql-ledgerMatch2.8.7
OR
sql-ledgersql-ledgerMatch2.8.8
OR
sql-ledgersql-ledgerMatch2.8.9
OR
sql-ledgersql-ledgerMatch2.8.10
OR
sql-ledgersql-ledgerMatch2.8.11
OR
sql-ledgersql-ledgerMatch2.8.12
OR
sql-ledgersql-ledgerMatch2.8.13
OR
sql-ledgersql-ledgerMatch2.8.14
OR
sql-ledgersql-ledgerMatch2.8.15
OR
sql-ledgersql-ledgerMatch2.8.16
OR
sql-ledgersql-ledgerMatch2.8.17
OR
sql-ledgersql-ledgerMatch2.8.18

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.034

Percentile

91.5%