CVE-2006-3861
 
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 does not use database creation permissions, which allows remote authenticated users to create arbitrary databases.
IBM Informix Dynamic Server (IDS) anterior a 9.40.xC7 y 10.00 anterior a 10.00.xC3 no utiliza permisos de creación de bases de datos, lo cual permite a usuarios autenticados remotamente crear bases de datos de su elección.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-07-26 CVE Reserved
- 2006-08-08 CVE Published
- 2023-10-04 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.pdf | X_refsource_misc | |
http://www.osvdb.org/27692 | Vdb Entry | |
http://www.securityfocus.com/archive/1/443133/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/443192/100/0/threaded | Mailing List | |
http://www.vupen.com/english/advisories/2006/3077 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28148 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21301 | 2018-10-17 | |
http://www-1.ibm.com/support/docview.wss?uid=swg21242921 | 2018-10-17 | |
http://www.securityfocus.com/bid/19264 | 2018-10-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 7.31 Search vendor "Ibm" for product "Informix Dynamic Server" and version "7.31" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.4 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.tc5 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.tc5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc1 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc2 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc3 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc5 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.xc5 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.xc5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 10.0 Search vendor "Ibm" for product "Informix Dynamic Server" and version "10.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 10.0.xc1 Search vendor "Ibm" for product "Informix Dynamic Server" and version "10.0.xc1" | - |
Affected
|