Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-5467

EPSS 5.04% · P90
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-5467

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-" instead of "--" and contains an inconsistent ID.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Yukihiro Matsumoto Ruby CGI模块畸形MIME数据拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Ruby是动态、开放源码的编程语言。 Ruby CGI模块在处理畸形用户请求时存在漏洞,远程攻击者可能利用此漏洞对服务器执行拒绝服务攻击。 如果攻击者所提交HTTP请求的多部分MIME中包含有无效的边界指示符,就可能在Ruby的CGI库中触发死循环,导致耗尽CUP资源。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-5467

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-5467

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-10-27 · 28 CVEs total

CVE-2006-5558HP-UX Software Distributor SWAsk本地格式串漏洞
CVE-2006-5571Cruiseworks 'Cws.exe' Doc参数缓冲区溢出漏洞
CVE-2006-5570Cruiseworks 'Cws.EXE' Doc目录遍历漏洞
CVE-2006-5569DataWizard FTPXQ Server 未明任意文件重写漏洞
CVE-2006-5568DataWizard MKD命令拒绝服务攻击漏洞
CVE-2006-5567Nullsoft Winamp Ultravox多个远程堆溢出漏洞
CVE-2006-5566Shop-Script 'index.php'CRLF注入漏洞
CVE-2006-5565MAXdev MD-Pro 任意HTTP报头CRLF序列注入漏洞
CVE-2006-5564MAXdev MD-Pro 'User.PHP'跨站脚本攻击漏洞
CVE-2006-5563雅虎通会议邀请空指针远程拒绝服务漏洞
CVE-2006-5562SourceForge 'database.php'远程文件包含漏洞
CVE-2006-5561Discuz! 'AdminCP.PHP' SQL注入漏洞
CVE-2006-5560Boesch ProgSys 'heading.php'跨站脚本攻击漏洞
CVE-2006-5559Microsoft IE ADODB.Connection对象Execute函数内存破坏漏洞
CVE-2006-4805Wireshark 'packet-xot.c'XOT的协议解析器
CVE-2006-5557HP-UX Software Distributor swpackage命令行参数本地栈溢出漏洞
CVE-2006-5556HP-UX LIBC TZ环境变量本地溢出漏洞
CVE-2006-5594University of British Columbia iPeer PHP远程文件包含漏洞
CVE-2006-5593Desknet 缓冲区溢出漏洞
CVE-2006-5592PacPoll 'adpoll.asp' Cookie安全绕过漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-5467

No comments yet


Leave a comment