Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-4950

EPSS 3.31% · P87
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-4950

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco IOS 访问验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IOS是Cisco设备所使用的操作系统。 Cisco IOS软件的某些版本中存在访问验证漏洞,远程攻击者可能利用此漏洞非授权获取对设备的访问。 如果设备上启用了SNMP的话,则有漏洞的版本就可能包含有硬编码的SNMP团体字符串cable-docsis。默认的团体字符串是由于无意中将这些设备识别为所支持的符合有线电缆数据服务接口规范(DOCSIS)的接口而导致的。如果设备配置了SNMP管理的话,就可能启用额外的读写团体字符串,允许经验丰富的攻击者获得对设备的特权访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-4950

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-4950

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-09-23 · 31 CVEs total

CVE-2006-4945DigitalWebShop多个远程文件包含漏洞
CVE-2006-4944ProgSys 'includes/pear/Net/DNS/RR.php'PHP远程文件包含漏洞
CVE-2006-4943Moodle 'course/jumpto.php' 敏感信息泄露漏洞
CVE-2006-4942Moodle 信息泄露漏洞
CVE-2006-4941Moodle 多个跨站脚本攻击漏洞
CVE-2006-4940Moodle 'login/forgot_password.php' 敏感信息泄露漏洞
CVE-2006-4939Moodle 'backup/backup_scheduled.php' 信息泄露漏洞
CVE-2006-4938Moodle 'help.php' 信息泄露漏洞
CVE-2006-4937Moodle 'lib/setup.php' 敏感信息泄露漏洞
CVE-2006-4936Moodle 输入验证错误漏洞
CVE-2006-4935Moodle 数据库模块未限制上传文件漏洞
CVE-2006-4949Drupal 跨站脚本攻击(XSS)漏洞
CVE-2006-4948TFTPDWIN 缓冲区溢出漏洞
CVE-2006-4947Drupal 搜索关键字模块跨站脚本攻击漏洞
CVE-2006-4946CMSDevelopment Business Card Web Builder'include/startup.inc.php'PHP远程文件包含漏洞
CVE-2005-4812SISCO OSI栈远程溢出漏洞
CVE-2006-4964MAXdev MDPro 跨站脚本攻击漏洞
CVE-2006-4963Exponent CMS 'index.php'目录遍历漏洞
CVE-2006-4962Php Blue Dragon 'pbd_engine.php'目录遍历漏洞
CVE-2006-4961Php Blue Dragon GetModuleConfig函数SQL注入漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-4950

No comments yet


Leave a comment