CVE-2006-0917
Last modified
CVE-2006-0917 is a vulnerability of currently unknown severity. Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Melange | Melange Chat System | 1.10 |
References
- http://secunia.com/advisories/18984Vendor Advisory
- http://secunia.com/advisories/18984Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0917?
How severe is CVE-2006-0917?
How do I fix CVE-2006-0917?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-0911NmService.exe in Ipswitch WhatsUp Professional 2006 allows r…
- CVE-2006-0912Oreka before 0.5 allows remote attackers to cause a denial o…
- CVE-2006-0913SQL injection vulnerability in whineatnews.pl in Bugzilla 2.…
- CVE-2006-0914Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not pro…
- CVE-2006-0915Bugzilla 2.16.10 does not properly handle certain characters…
- CVE-2006-0916Bugzilla 2.19.3 through 2.20 does not properly handle "//" s…
- CVE-2006-0918Buffer overflow in RITLabs The Bat! 3.60.07 allows remote at…
- CVE-2006-0919SQL injection vulnerability in index.php (aka the login page…
- CVE-2006-0920Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server…
- CVE-2006-0921Multiple directory traversal vulnerabilities in connector.ph…
- CVE-2006-0922CubeCart 3.0 through 3.6 does not properly check authorizati…
- CVE-2006-0923Multiple cross-site scripting (XSS) vulnerabilities in MyPHP…
Are you affected by CVE-2006-0917?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
