First published: Wed Jan 11 2006(Updated: )
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hummingbird Enterprise Collaboration | <=5.21 | |
Hummingbird Enterprise Collaboration | =5.2 | |
Hummingbird | <=5.21 | |
Hummingbird | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0174 is considered a medium severity vulnerability due to its potential for information disclosure.
To fix CVE-2006-0174, upgrade to Hummingbird Collaboration version 5.22 or later, which addresses this vulnerability.
CVE-2006-0174 can expose sensitive information such as intranet IP addresses and valid parameter value enumerations.
CVE-2006-0174 affects Hummingbird Collaboration versions 5.21 and earlier, including Hummingbird Enterprise Collaboration 5.21 and earlier.
Organizations using vulnerable versions of Hummingbird Collaboration or Hummingbird Enterprise Collaboration are impacted by CVE-2006-0174.