CVE-2006-0232
Summary
| CVE | CVE-2006-0232 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-25 01:02:00 UTC |
| Updated | 2018-10-19 15:43:00 UTC |
| Description | Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Antivirus Scan Engine | 5.0.0.24 | All | All | All |
| Application | Symantec | Antivirus Scan Engine | 5.0.0.24 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec AntiVirus Scan Engine Multiple Remote Vulnerabilities | BID | www.securityfocus.com | |
| Symantec Scan Engine Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| 404 Not Found | CONFIRM | www.symantec.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability | VULNWATCH | archives.neohapsis.com | Exploit, Patch, Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityTracker.com Archives - Symantec Scan Engine Lets Remote Users Access the System and Download Files | SECTRACK | securitytracker.com | |
| SecurityReason | SREASON | securityreason.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| SecurityReason | SREASON | securityreason.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.