Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2006-6572

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Citrix Advanced Access Control (AAC) Option 4.0和Access Gateway 4.2 with Advanced Access Control 4.2的20061114之前版本存在未明漏洞,当Browser-Only访问功能启用时,远程认证用户可通过特定登录方法来绕过访问策略。

AI Predicted 7.4 Difficulty: Moderate EPSS 1.48% · P73
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2006-6572

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a different issue than CVE-2006-4846. NOTE: some of these details are obtained from third party information.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Citrix Access Gateway Advanced Browser-Only 未明安全绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Citrix Advanced Access Control (AAC) Option 4.0和Access Gateway 4.2 with Advanced Access Control 4.2的20061114之前版本存在未明漏洞,当Browser-Only访问功能启用时,远程认证用户可通过特定登录方法来绕过访问策略。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2006-6572

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-6572

登录查看更多情报信息。

Vendor Advisories for CVE-2006-6572 (6)

Other References for CVE-2006-6572 (2)

Same Patch Batch · n/a · 2006-12-15 · 46 CVEs total

CVE-2006-6594 ScriptMate User Manager 'usermessages.asp'SQL注入漏洞
CVE-2006-6564 FileZilla Server STOR命令畸形自变量拒绝服务攻击漏洞
CVE-2006-6566 mxBB Profile Control Panel (CPanel)模块PHP远程文件包含漏洞
CVE-2006-6569 GenesisTrader 'form.php'敏感信息泄露漏洞
CVE-2006-6570 GenesisTrader 'upload.php' 未限制文件上载漏洞
CVE-2006-6571 GenesisTrader 'form.php'跨站脚本攻击(XSS)漏洞
CVE-2006-6573 Citrix Access Gateway未明信息泄露漏洞
CVE-2006-6105 GNOME显示管理器GDMChooser本地格式串处理漏洞
CVE-2006-6568 MXBB KB_Mods Module 'KB_Constants.PHP'目录遍历漏洞
CVE-2006-6595 ScriptMate User Manager 多个SQL注入漏洞
CVE-2006-6563 ProFTPD mod_ctrls模块本地栈溢出漏洞
CVE-2006-6593 PHPBB Amazonia Component 'Zufallscodepart.PHP'远程文件包含漏洞
CVE-2006-6592 Bloq Page[Path]多个远程文件包含漏洞
CVE-2006-6591 Exlor 'template.php' PHP远程文件包含漏洞
CVE-2006-6590 AR Memberscript 'usercp_menu.php'PHP远程文件包含漏洞
CVE-2006-6589 Apache Open For Business Project和Opentaps 跨站脚本漏洞
CVE-2006-6588 Apache Open For Business Project 电子商务组件未明权限漏洞
CVE-2006-6587 Apache Open For Business Project 电子商务组件跨站脚本攻击漏洞
CVE-2006-6586 Vortex Blog 'a0.1_nonfunc'多个PHP远程文件包含漏洞
CVE-2006-6585 Mozilla Firefox Extensions manager扩展名漏洞

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-6572

No comments yet


Leave a comment