Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-2306

EPSS 0.02% · P4
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-2306

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Adobe Macromedia ColdFusion MX/ JRun 权限提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Jrun是由Allaire公司开发的JAVA服务器软件。 ColdFusion MX 是一个适用于Windows和Solaris的网站应用程序服务器程序,为开发者提供了一个高效率的脚本环境以及整合的搜索和图表绘制功能。 Macromedia JRun 4.0、ColdFusion MX 6.1和7.0中的竞争条件存在权限提升漏洞。 当负载较重时,竞争条件会导致JRun将重复的认证令牌指派给多个会话,这可让认证用户作为其他用户获取特权。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-2306

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-2306

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-07-19 · 58 CVEs total

CVE-2005-2305DG Remote Control Server 拒绝服务漏洞
CVE-2005-2320WebCalendar assistant_edit.php 权限提升漏洞
CVE-2005-2323Class-1 Forum /Clever Copy SQL注入漏洞
CVE-2005-2322class-1 Forum users.php 跨站脚本漏洞
CVE-2005-2321CaLogic CLPATH参数 PHP远程文件包含漏洞
CVE-2005-2324Clever Copy results.php/categorysearch.php 跨站脚本漏洞
CVE-2005-2310Nullsoft winamp mp3 ID3v2 缓冲区溢出漏洞
CVE-2005-2309Opera Software Opera 资源管理错误漏洞
CVE-2005-2308Microsoft Internet Explorer JPEG image 缓冲区溢出漏洞
CVE-2005-2307Microsoft windows网络连接管理器 netman.dll 拒绝服务漏洞
CVE-2005-2311SMS symlink符号链接攻击漏洞
CVE-2005-2304Microsoft Internet Explorer安全漏洞
CVE-2005-2302PowerDNS recursion 拒绝服务漏洞
CVE-2005-2301PowerDNS LDAP query 拒绝服务漏洞
CVE-2005-2300Skype skype_profile.jpg 符号链接攻击漏洞
CVE-2005-2299Simple Message Board 跨站脚本漏洞
CVE-2005-2298BitDefender attachment 绕过安全机制漏洞
CVE-2005-2297Sybase EAServer TreeAction.do 堆栈溢出漏洞
CVE-2005-2196Apple AirPort WEP key 安全限制绕过漏洞
CVE-2005-1851EKG 任意shell命令执行漏洞

Showing top 20 of 58 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-2306

No comments yet


Leave a comment