CVE-2006-2734
Summary
| CVE | CVE-2006-2734 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-01 10:02:00 UTC |
| Updated | 2018-10-18 16:41:00 UTC |
| Description | enter.asp in Mini-Nuke 2.3 and earlier makes it easier for remote attackers to conduct password guessing attacks by setting the guvenlik parameter to the same value as the hidden gguvenlik parameter, which bypasses a verification step because the gguvenlik parameter is assumed to be immutable by the attacker. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers | MISC | www.nukedx.com | Exploit |
| MiniNuke v2.x Multiple Remote Vulnerabilities - CXSecurity.com | SREASON | securityreason.com | |
| Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers | MISC | www.nukedx.com | Exploit, Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.