← All CVEs

CVE-2006-0230

high · 10

Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.

10
CVSS
16.1%
EPSS (exploit prob.)
97th
EPSS percentile
2006-04-25
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
symantecantivirus_scan_engine5.0.0.24

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-0230