CVE-2006-3830

UnknownEPSS 0.81%

Last modified

CVE-2006-3830 is a vulnerability of currently unknown severity. The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. NOTE: because the uploaded files cannot be accessed through HTTP, this issue is a vulnerability only if there is a likely usage pattern in which the files would be opened or executed by local users, e.g., malware files with names that entice local users to open the files.. EPSS estimates a 0.81% chance of exploitation in the next 30 days.

Description

The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. NOTE: because the uploaded files cannot be accessed through HTTP, this issue is a vulnerability only if there is a likely usage pattern in which the files would be opened or executed by local users, e.g., malware files with names that entice local users to open the files.

Metrics

EPSS Probability
0.81%

52.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Kailash NadhBoastmachine2.5
Kailash NadhBoastmachine2.7
Kailash NadhBoastmachine2.8
Kailash NadhBoastmachine2.9b
Kailash NadhBoastmachine3.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-3830?
The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. NOTE: because the uploaded files cannot be accessed through HTTP, this issue is a vulnerability only if there is a likely usage pattern in which the files would be opened or executed by local users, e.g., malware files with names that entice local users to open the files.
How severe is CVE-2006-3830?
Severity scoring for CVE-2006-3830 is pending analysis. The EPSS model estimates a 0.81% probability of exploitation in the next 30 days.
How do I fix CVE-2006-3830?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-3830?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST