« Volver al listado

CVE-2006-5956

Estado: ModificadaBaja (2.1)—

XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-5956",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-11-17T00:07:00.000",
  "references": [
    {
      "url": "http://lostmon.blogspot.com/2006/11/phprunner-database-credentials.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/22863",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1017218",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/30363",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/21054",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lostmon.blogspot.com/2006/11/phprunner-database-credentials.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/22863",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1017218",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/30363",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/21054",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file."
    },
    {
      "lang": "es",
      "value": "XLineSoft PHPRunner 3.1 stores el (1)nombre del servidor la base de datos, (2) los nombres de la base de datos, (3) nombre de usuario y (4)contraseñas en texto plano en %WINDIR%\\PHPRunner.ini, lo cual permiten a un usuario local obtener información sensible a través de la lectura de ficheros."
    }
  ],
  "lastModified": "2026-06-16T22:32:12.360",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xlinesoft:phprunner:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DBC4CF9-4F07-4439-81AB-BFE0D55A24B2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}