Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-6184

EPSS 81.30% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-6184

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
AT-TFTP Server超长文件名远程缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
AT-TFTP Server是一款免费的基于Windows的TFTP服务器,用于在PC和Allied Telesis路由器及一些交换机之间传输软件发布、补丁、脚本等。 AT-TFTP Server在处理带有超长文件名参数的请求时存在漏洞,远程攻击者可能利用此漏洞在服务器上执行任意指令。 AT-TFTP Server在处理传送给GET或PUT命令的超长文件名(大于227个字节)时存在缓冲区溢出。如果攻击者向服务器发送了恶意报文的话就会触发这个漏洞,导致拒绝服务或执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-6184

#POC DescriptionSource LinkShenlong Link
1This is a python-based standalone exploit for CVE-2006-6184. This exploit triggers a stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service or execute arbitrary code.https://github.com/shauntdergrigorian/cve-2006-6184POC Details
2simplified version of https://github.com/shauntdergrigorian/cve-2006-6184https://github.com/b03902043/CVE-2006-6184POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-6184

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-12-01 · 41 CVEs total

CVE-2006-6187ClickTech Click Gallery 多个SQL注入漏洞
CVE-2006-6218dev4u CMS中的index.php 多个SQL注入漏洞
CVE-2006-6219Dev4U CMS Index.PHP 多个跨站脚本漏洞
CVE-2006-6220Recipes Website 多个SQL注入漏洞
CVE-2006-6180Expinion.net iNews Publisher Articles.ASP 跨站脚本攻击漏洞
CVE-2006-6181ClickContact Default.ASP多个SQL注入漏洞
CVE-2006-6182GNotebook本地信息泄露漏洞
CVE-2006-61833Com TFTP超长传输模式字段远程缓冲区溢出漏洞
CVE-2006-6185Wabbit PHP Gallery Dir参数目录遍历漏洞
CVE-2006-6186enomphp 多个目录遍历漏洞
CVE-2006-6217PHP-Nuke Mermaid 1.2模块 formdisp.php PHP远程文件包含漏洞
CVE-2006-6188ClickTech Click Gallery view_search.asp 跨站点脚本漏洞
CVE-2006-6189Clickblog Displaycalendar.ASP SQL注入漏洞
CVE-2006-6190Anna IRC Bot Anna.PL SQL注入漏洞
CVE-2006-61918pixel.net simpleblog admin/edit.asp SQL注入漏洞
CVE-2006-61928pixel.net SimpleBlog 权限认证和访问控制漏洞
CVE-2006-6193BasicForum EDIT.ASP SQL注入漏洞
CVE-2006-6194Ultimate Survey Pro index.asp 多个SQL注入漏洞
CVE-2006-6195Fixit iDMS Pro Image Gallery 多个SQL注入漏洞
CVE-2006-6196Fixit iDMS Pro Image Gallery 跨站脚本攻击漏洞

Showing top 20 of 41 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-6184

No comments yet


Leave a comment