Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-2539

EPSS 0.07% · P20
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-2539

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the cleartext passwords via the getSelectedText function in javax.swing.JPasswordField component.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sybase EAServer JPasswordField口令 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sybase EAServer(Enterprise Application Server)是美国Sybase公司的一款基于J2EE的、企业级的应用服务器。该服务器提供企业级Web Site、分布式和主从式架构的解决方案。 在UNIX和LINUX平台上的J2EE或Java GUI应用程序中使用口令字段时存在安全漏洞。 1 如果用户在GUI应用程序的口令提示对话框中输入了口令但没有点击"确定"或"输入"的话,就会保持口令对话框一直打开,因此其他可以物理访问机器的用户就可以访问所输入的口令。通过远程控制软件访
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-2539

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-2539

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-05-22 · 42 CVEs total

CVE-2006-2506Sphider Search.PHP 多个跨站脚本攻击漏洞
CVE-2006-2524UseBB 跨站脚本攻击(XSS)漏洞
CVE-2006-2525UseBB 会员列表搜索模块 SQL注入漏洞
CVE-2006-2526Power Place PHP Easy Galerie Index.PHP 远程文件包含漏洞
CVE-2006-2527PHPBazar Admin.PHP 认证绕过漏洞
CVE-2006-2528phpBazar classified_right.php 远程文件包含漏洞
CVE-2006-2512ILF Hitachi EUR 未明SQL注入漏洞
CVE-2006-2513Sun Java 系统目录服务器 认证绕过漏洞
CVE-2006-2503DeluxeBB misc.php SQL注入漏洞
CVE-2006-2504AZBoard 多个SQL注入漏洞
CVE-2006-2505Oracle 10g DBMS_EXPORT_EXTENSION存储过程 SQL注入漏洞
CVE-2006-2523phpListPro config.php PHP远程文件包含漏洞
CVE-2006-2507Foing 多个远程文件包含漏洞
CVE-2006-2508YourFreeWorld.com Stylish Text Ads Script tr1.php SQL注入漏洞
CVE-2006-2509YourFreeWorld Short Url & Url Tracker Script login.php SQL注入漏洞
CVE-2006-2510YourFreeWorld Short Url & Url Tracker Script URL提交表单 跨站脚本攻击(XSS)漏洞
CVE-2006-2511FrontRange iHEAT ActiveX版本 输入验证漏洞
CVE-2006-2185Novell NetWare PORTAL.NLM 本地信息泄露漏洞
CVE-2006-1857Linux Kernel SCTP HB-ACK组块 拒绝服务漏洞
CVE-2006-1858Linux Kernel SCTP 多个远程拒绝服务漏洞

Showing top 20 of 42 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-2539

No comments yet


Leave a comment