« Volver al listado

CVE-2006-6982

Estado: ModificadaMedia (5)—

3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-6982",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-02-08T18:28:00.000",
  "references": [
    {
      "url": "http://3proxy.ru/0.5.3g/Changelog.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38205",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://3proxy.ru/0.5.3g/Changelog.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38205",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials."
    },
    {
      "lang": "es",
      "value": "3proxy 0.5 hasta 0.5.2 no ofrece autenticación NTLM antes de la autenticación básica, lo cual podría provocar que navegadores con soporte incompleto de RGC2616/RFC2617 utilicen autenticación básica en texto claro incluso si NTLM está disponible, lo cual facilita a los atacantes el robo de credenciales."
    }
  ],
  "lastModified": "2026-06-16T22:34:10.010",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7086CA7A-6A00-41BD-B965-20BD49982A6D"
            },
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87BC7A0B-1687-4DC6-B8BC-043D3A4588D4"
            },
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "597A63F7-0EB5-4E5E-A992-5F5A9F3D1496"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "The link is to the vendor's changelog.  The vendor's download site is:\r\nhttp://3proxy.ru/download/\r\n\r\nFor the latest build."
}