Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-1620

EPSS 1.14% · P79
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-1620

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Hosting 控件 AccountActions.asp 权限许可和访问控制漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hosting 控件2002 RC 1版本的admin/accounts/AccounstActions.asp文件允许远程攻击者修改其它用户的密码,方式可能是通过一个带UserName参数和设置为TRUE的PassCheck参数的"Update User"行为类型。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-1620

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-1620

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-04-05 · 15 CVEs total

CVE-2006-1631Cisco 11500内容服务交换机HTTP压缩请求处理远程拒绝服务漏洞
CVE-2006-1055linux内核SYSFS sysfs/file.c 本地拒绝服务漏洞
CVE-2006-0051Kaffeine http_peek()函数远程溢出漏洞
CVE-2006-0401Apple MAC OS X 未明漏洞
CVE-2006-1616Adanced Poll 多个SQL注入漏洞
CVE-2006-1617Advanced Poll 多个跨站脚本攻击
CVE-2006-1618Doomsday con_main.c 多个远程格式化字符串漏洞
CVE-2006-1619IBM WebSphere Application Sever 拒绝服务攻击漏洞
CVE-2006-1621Hosting 控件 saveuploadfiles.asp 目录遍历漏洞
CVE-2006-1622PHPSellect linksubmit 跨站脚本攻击漏洞
CVE-2006-1623Andries Bruinsma main.php 未明漏洞
CVE-2006-1624Linux sysklogd 拒绝服务攻击
CVE-2006-1625MyBulletinBoard inc/functions_post.php 跨站脚本攻击漏洞
CVE-2006-1626Microsoft Internet Explorer输入验证错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-1620

No comments yet


Leave a comment