« Volver al listado

CVE-2006-6229

Estado: ModificadaMedia (5)—

Codewalkers ltwCalendar (aka PHP Event Calendar) before 4.2.1 logs failed passwords, which might allow attackers to infer correct passwords from the log file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-6229",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-12-02T02:28:00.000",
  "references": [
    {
      "url": "http://ltwcalendar.sourceforge.net/changelog.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ltwcalendar.sourceforge.net/changelog.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Codewalkers ltwCalendar (aka PHP Event Calendar) before 4.2.1 logs failed passwords, which might allow attackers to infer correct passwords from the log file."
    },
    {
      "lang": "es",
      "value": "El código de ltwCalendar (también conocido como PHP Event Calendar) anterior a 4.2.1 registra contraseñas fallidas, lo cual permitiría a un atacante remoto averiguar la contraseña correcta desde el fichero de log."
    }
  ],
  "lastModified": "2026-06-16T22:32:43.290",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:codewalkers:ltwcalendar:4.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28F14FBF-66CB-45C4-A516-08C91CF4B734"
            },
            {
              "criteria": "cpe:2.3:a:codewalkers:ltwcalendar:4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B632DBF1-D6AA-4A3D-A0BE-0C3B9D98D988"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}