Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-0844

EPSS 0.47% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-0844

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Leif M. Wright Blog.CGI授权绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Leif M. Wright's Blog 3.5在通过cookie认证管理员时不进行密码比较,这使远程攻击者可以通过设置blogAdmin cookie来绕过登录认证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-0844

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-0844

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-02-22 · 17 CVEs total

CVE-2006-0848Apple Safari Shell命令执行漏洞
CVE-2006-0834Uniden UIP1868P VoIP电话和路由器web配置工具默认密码敏感信息泄露漏洞
CVE-2006-0835MitriDAT Web Calendar Pro Dropbase.PHP SQL注入漏洞
CVE-2006-0836Mozilla Thunderbird地址薄导入远程拒绝服务漏洞
CVE-2006-0837Micromuse Netcool/Neusecure NS帐户密码泄露漏洞
CVE-2006-0838Micromuse Netcool/Neusecure NS帐户密码泄露漏洞
CVE-2006-0839Snort Frag3 Processor数据包碎片逃避检测漏洞
CVE-2006-0840Mantis多个输入验证漏洞
CVE-2006-0841Mantis 多个跨站脚本攻击漏洞
CVE-2006-0842Calacode @Mail 跨站脚本攻击漏洞
CVE-2006-0843Leif M. Wright Blog信息泄露漏洞
CVE-2006-0845Leif M. Wright's Blog 配置邮件发送路径任意程序执行漏洞
CVE-2006-0846Leif M. Wright Blog 多个跨站脚本攻击漏洞
CVE-2006-0847CherryPy StaticFilter目录遍历漏洞
CVE-2006-0832Webpagecity WPC easy 'admin.asp'SQL注入漏洞
CVE-2006-0833Barracuda Directory多个跨站脚本攻击漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-0844

No comments yet


Leave a comment