« Volver al listado

CVE-2006-6705

Estado: ModificadaMedia (5)—

Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allow remote attackers to bypass authentication mechanisms on web pages via unknown vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-6705",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-12-23T01:28:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/23399",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.hitachi-support.com/security_e/vuls_e/HS06-016_e/01-e.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/5114",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23399",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.hitachi-support.com/security_e/vuls_e/HS06-016_e/01-e.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/5114",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple unspecified vulnerabilities in the template files in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allow remote attackers to bypass authentication mechanisms on web pages via unknown vectors."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades no especificadas en los ficheros template en Soumu Workflow para Groupmax 01-00 hasta la01-01, Soumu Workflow 02-00 hasta la 03-03, y Koukyoumuke Soumu Workflow 01-00 hasta la 01-01 permite a un atacante remoto evitar los mecanismos de validación sobre páginas web a través de vectores desconocidos."
    }
  ],
  "lastModified": "2026-06-16T22:33:38.150",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:soumu:koukyoumuke_soumu_workflow:01-00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7237C84-D299-46C2-94AA-AC6C3AADB1AE"
            },
            {
              "criteria": "cpe:2.3:a:soumu:koukyoumuke_soumu_workflow:01-01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAB3C969-9EBB-474A-B1DB-9BBC1C6C2E46"
            },
            {
              "criteria": "cpe:2.3:a:soumu:soumo_workflow:01_00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B28264C-01AA-4EA3-9D31-2A40DB4B0342"
            },
            {
              "criteria": "cpe:2.3:a:soumu:soumo_workflow:01_01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B2AC218-56E1-4114-9D54-39CB094A207D"
            },
            {
              "criteria": "cpe:2.3:a:soumu:soumu_workflow:02-00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "026F1097-2F73-4158-8AE7-EFBF69068B7E"
            },
            {
              "criteria": "cpe:2.3:a:soumu:soumu_workflow:02-01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2915D11-3937-47D2-93F4-0F92F75D7AE6"
            },
            {
              "criteria": "cpe:2.3:a:soumu:soumu_workflow:03-03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE8E8D7A-65C5-4245-9BBD-BEB8C8F1B36D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}