CVE-2006-2734
Last modified
CVE-2006-2734 is a vulnerability of currently unknown severity. enter.asp in Mini-Nuke 2.3 and earlier makes it easier for remote attackers to conduct password guessing attacks by setting the guvenlik parameter to the same value as the hidden gguvenlik parameter, which bypasses a verification step because the gguvenlik parameter is assumed to be immutable by the attacker.. EPSS estimates a 1.54% chance of exploitation in the next 30 days.
Description
enter.asp in Mini-Nuke 2.3 and earlier makes it easier for remote attackers to conduct password guessing attacks by setting the guvenlik parameter to the same value as the hidden gguvenlik parameter, which bypasses a verification step because the gguvenlik parameter is assumed to be immutable by the attacker.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mini-Nuke | Mini-Nuke | <= 2.3 |
References
- http://www.nukedx.com/?viewdoc=31Exploit, Vendor Advisory
- http://www.nukedx.com/?viewdoc=31Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2734?
How severe is CVE-2006-2734?
How do I fix CVE-2006-2734?
Are you affected by CVE-2006-2734?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
