Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-2428

EPSS 1.04% · P78
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-2428

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be bypassed. NOTE: some of these details are obtained from third party information, since the raw source is vague.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
DUware Dubanner add.asp可 任意文件上传漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DUware DUbanner 3.1中的add.asp可以使远程攻击者通过上传带有任意扩展名的诸如ASP等文件,执行任意代码。可能由客户端可绕过的执行所致。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-2428

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-2428

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-05-17 · 21 CVEs total

CVE-2006-2429ibm websphere_application_server 未明漏洞
CVE-2006-2438Caucho Resin viewfile程序组件 目录遍历漏洞
CVE-2006-2437Caucho Resin 某CGI程序 输入验证漏洞
CVE-2006-2436WebSphere Application Server FFDC日志 信息泄露漏洞
CVE-2006-2435ibm websphere_application_server 未明漏洞
CVE-2006-2434WebSphere 普通配置模块 + CommonArchive J2EE 模块未明漏洞
CVE-2006-2433ibm websphere_application_server 未明漏洞
CVE-2006-2432IBM WebSphere Application Server LTPA令牌 权限许可和访问控制漏洞
CVE-2006-2431IBM WebSphere 500 Internal Server Error 跨站脚本攻击漏洞
CVE-2006-2430IBM WebSphere Application Server addNode.log 信息泄露漏洞
CVE-2005-4802Flexbackup 临时文件漏洞
CVE-2006-2427多个版本 freshclam config-file命令 信息泄露漏洞
CVE-2006-2426Sun Java Runtime Environment Font.createFont函数 拒绝服务漏洞
CVE-2006-2425PHPRemoteView PRV.PHP 多个跨站脚本攻击漏洞
CVE-2006-2424EZUserManager EZusermanager_pwd_forgott.PHP 远程文件包含漏洞
CVE-2006-2423Confixx Index.PHP 跨站脚本攻击漏洞
CVE-2006-2422phpCOIN Email 信息泄露漏洞
CVE-2006-2421Pragma FortressSSH SSH_MSG_KEXINIT 远程缓冲区溢出漏洞
CVE-2006-1953Caucho Resin 用户请求 目录遍历漏洞
CVE-2005-4803Graphviz不安全临时文件创建漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-2428

No comments yet


Leave a comment