Vulnerabilities > CVE-2006-0174 - Multiple vulnerability in Hummingbird Collaboration and Enterprise Collaboration

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
hummingbird
exploit available

Summary

Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.

Exploit-Db

descriptionHummingbird Collaboration Application Cookie Internal Network Information Disclosure. CVE-2006-0174. Webapps exploit for cgi platform
idEDB-ID:27062
last seen2016-02-03
modified2006-01-10
published2006-01-10
reporterLuca Carettoni
sourcehttps://www.exploit-db.com/download/27062/
titleHummingbird Collaboration Application Cookie Internal Network Information Disclosure