« Volver al listado

CVE-2006-5832

Estado: ModificadaMedia (5)—💥 Exploit

All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-5832",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-11-10T01:07:00.000",
  "references": [
    {
      "url": "http://securityreason.com/securityalert/1839",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=478370",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/450701/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/20931",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30052",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1839",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=478370",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/450701/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/20931",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30052",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages."
    },
    {
      "lang": "es",
      "value": "All In One Control Panel (AIOCP) 1.3.007 y versiones anteriores permite a atacantes remotos obtener la ruta completa al servidor secuencias de comandos web o HTML de su elección  mediante peticiones concretas a (1) public/code/cp_dpage.php, posiblemente involucrando al parámetro aiocp_dp[], (2) public/code/cp_show_ec_products.php, posiblemente involucrando al parámetro order_field[], y (3) public/code/cp_show_page_help.php, posiblemente involucrando al parámetro hp[], que revela la ruta en varios mensajes de error."
    }
  ],
  "lastModified": "2026-06-16T22:31:58.003",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7D4D34B-5856-449E-B146-0414B01E357B"
            },
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.001:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CBBE828-3E9C-4267-B315-DD57054F1450"
            },
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.002:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA2A2CE9-4A2F-40F4-81D7-B090900129FE"
            },
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.003:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "389615A9-6D11-4555-98FE-B4969DECF50C"
            },
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.004:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63B0794D-0766-4A11-9613-1568E3A20446"
            },
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.005:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCBD2F9E-97C0-456B-8475-862241DF437D"
            },
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06C22893-1E2F-48B2-B571-358145734B8F"
            },
            {
              "criteria": "cpe:2.3:a:aiocp:aiocp:1.3.007:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAB6E40E-8937-4563-BB67-C9212A2652D6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}