Vulnerability Name:

CVE-2006-1466 (CCN-26634)

Assigned:2006-05-23
Published:2006-05-23
Updated:2017-07-20
Summary:Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.
CVSS v3 Severity:4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2006-1466

Source: CCN
Type: Apple Web site
Tools - Downloads

Source: APPLE
Type: UNKNOWN
APPLE-SA-2006-05-23

Source: CCN
Type: Apple Product Security Mailing List, Tue, 23 May 2006 14:53:38 -0700
APPLE-SA-2006-05-23 Xcode Tools 2.3

Source: CCN
Type: SA20267
Apple Xcode WebObjects Plugin Access Control Vulnerability

Source: SECUNIA
Type: UNKNOWN
20267

Source: CCN
Type: SECTRACK ID: 1016143
Apple Xcode Tools Grants Remote Access to WebObjects Projects

Source: SECTRACK
Type: UNKNOWN
1016143

Source: OSVDB
Type: UNKNOWN
25889

Source: CCN
Type: OSVDB ID: 25889
Apple Mac OS X Xcode Tools WebObjects Plugin Project Manipulation

Source: BID
Type: UNKNOWN
18091

Source: CCN
Type: BID-18091
Apple Xcode Tools WebObjects Unauthorized Remote Access Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2006-1950

Source: XF
Type: UNKNOWN
xcode-webobjects-unauth-access(26634)

Source: XF
Type: UNKNOWN
xcode-webobjects-unauth-access(26634)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:apple:xcode:*:*:*:*:*:*:*:* (Version <= 2.2)

  • Configuration 2:
  • cpe:/o:apple:mac_os_x:10.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apple:xcode:2.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    apple xcode *
    apple mac os x 10.4
    apple xcode 2.2