CVE-2006-5932

Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kahua:kahua:0.1:*:*:*:*:*:*:*
cpe:2.3:a:kahua:kahua:0.2:*:*:*:*:*:*:*
cpe:2.3:a:kahua:kahua:0.3:*:*:*:*:*:*:*
cpe:2.3:a:kahua:kahua:0.4:*:*:*:*:*:*:*
cpe:2.3:a:kahua:kahua:0.5:*:*:*:*:*:*:*
cpe:2.3:a:kahua:kahua:0.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:21

Type Values Removed Values Added
References () http://secunia.com/advisories/22785 - Patch, Vendor Advisory () http://secunia.com/advisories/22785 - Patch, Vendor Advisory
References () http://www.kahua.org/cgi-bin/kahua.fcgi/kahua-web/show/KSA/KSA2006-001 - Patch, Vendor Advisory () http://www.kahua.org/cgi-bin/kahua.fcgi/kahua-web/show/KSA/KSA2006-001 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/21074 - () http://www.securityfocus.com/bid/21074 -
References () http://www.timedia.co.jp/news/2467470581 - Patch, Vendor Advisory () http://www.timedia.co.jp/news/2467470581 - Patch, Vendor Advisory
References () http://www.vupen.com/english/advisories/2006/4486 - () http://www.vupen.com/english/advisories/2006/4486 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/30206 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/30206 -

Information

Published : 2006-11-16 00:07

Updated : 2025-04-09 00:30


NVD link : CVE-2006-5932

Mitre link : CVE-2006-5932

CVE.ORG link : CVE-2006-5932


JSON object : View

Products Affected

kahua

  • kahua