CVE-2006-2737
published 2006-06-01CVE-2006-2737: utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
3.35%
87.2th percentile
utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nukedit | nukedit | <= 4.9.6 | — |
| nukedit | nukedit | — | — |
| nukedit | nukedit | — | — |
| nukedit | nukedit | — | — |
| nukedit | nukedit | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/20348http://securityreason.com/securityalert/1013http://www.kapda.ir/advisory-337.htmlhttp://www.kapda.ir/attach-1661-nukedit.txthttp://www.securityfocus.com/archive/1/435311/100/0/threadedhttp://www.securityfocus.com/bid/18157http://www.vupen.com/english/advisories/2006/2052https://exchange.xforce.ibmcloud.com/vulnerabilities/26951http://secunia.com/advisories/20348http://securityreason.com/securityalert/1013http://www.kapda.ir/advisory-337.htmlhttp://www.kapda.ir/attach-1661-nukedit.txthttp://www.securityfocus.com/archive/1/435311/100/0/threadedhttp://www.securityfocus.com/bid/18157http://www.vupen.com/english/advisories/2006/2052https://exchange.xforce.ibmcloud.com/vulnerabilities/26951
2006-06-01
Published