CVE-2006-3398
Summary
| CVE | CVE-2006-3398 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-06 20:05:00 UTC |
| Updated | 2011-03-08 02:38:00 UTC |
| Description | The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pkr Internet | Taskjitsu | 0.1 | All | All | All |
| Application | Pkr Internet | Taskjitsu | 2.0 | All | All | All |
| Application | Pkr Internet | Taskjitsu | 0.1 | All | All | All |
| Application | Pkr Internet | Taskjitsu | 2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| www.pkrinternet.com/taskjitsu/task/3400 | MISC | www.pkrinternet.com | |
| www.pkrinternet.com/download/RELEASE-NOTES.txt | CONFIRM | www.pkrinternet.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.