Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2006-0232

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.
0
Attacker Value
Unknown

CVE-2006-0231

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.
0
Attacker Value
Unknown

CVE-2006-0230

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.
0