« Volver al listado

CVE-2006-5258

Estado: ModificadaMedia (5.1)—

The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that is not sanitized before Aspell is invoked.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-5258",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-10-12T22:07:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0306.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://editor.asbrusoft.com/page.php/id=727",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/22344",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/22353",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/22472",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wcm.asbrusoft.com/page.php/id=791",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/20544",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4004",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4060",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4061",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0306.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://editor.asbrusoft.com/page.php/id=727",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/22344",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/22353",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/22472",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://wcm.asbrusoft.com/page.php/id=791",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/20544",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4004",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4060",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4061",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that is not sanitized before Aspell is invoked."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad sin especificar en la comprobación ortográfica de (1) Asbru Web Content Management versiones anteriores a 6.1.22, (2) Asbry Web Content Editor anterior a 6.0.22, y (3) Asbry Website Manager anterior a 6.0.22 permite a atacantes remotos ejecutar comandos de su elección mediante un parámetro no especificado que no se limpia antes de que se invoque a Aspell."
    }
  ],
  "lastModified": "2026-06-16T22:30:50.940",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:asbru_software:asbru_web_content_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC5E064E-BF03-43C4-BCE9-D297F2AD3FF1",
              "versionEndIncluding": "6.1.20"
            },
            {
              "criteria": "cpe:2.3:a:asbru_software:asbru_web_content_management:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "036B68FB-C72F-4796-80DC-742E1D15E4EE"
            },
            {
              "criteria": "cpe:2.3:a:asbru_software:asbru_web_content_management:6.0.17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25652B15-502A-4F05-9032-A1D0624ADEA1"
            },
            {
              "criteria": "cpe:2.3:a:asbru_software:asbru_web_content_management:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1FF9CE0-7FBC-47CE-8D84-CDB9F2C5C74A"
            },
            {
              "criteria": "cpe:2.3:a:asbru_software:asbru_web_content_management:6.1.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "602B6F63-97FF-4288-8764-D47D19C3B79B"
            },
            {
              "criteria": "cpe:2.3:a:asbru_software:asbru_website_manager:6.0.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08E0A460-41A8-47C9-9823-995D9714716E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}