CVE-2006-2617
Summary
| CVE | CVE-2006-2617 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-26 01:06:00 UTC |
| Updated | 2018-10-18 16:40:00 UTC |
| Description | (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be resultant from SQL injection. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alstrasoft | Webhost Directory | 1.2 | All | All | All |
| Application | Alstrasoft | Webhost Directory | 1.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| AlstraSoft Web Host Directory SQL Injection and Script Insertion - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| AlstraSoft Web Host Directory v1.2 - CXSecurity.com | SREASON | securityreason.com | |
| HyperStop Web Host Directory SQL Injection and Script Insertion - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| The SitePoint Forums | MISC | www.sitepoint.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.