PT-2006-6201 · Planet+1 · Iplanet Messaging Server+1
Publicado
2006-10-24
·
Atualizado
2017-07-20
·
CVE-2006-5486
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Java System Messaging Server versions 6.0 through 6.2
iPlanet Messaging Server version 5.2
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to execute arbitrary Javascript via crafted messages. This could potentially lead to unauthorized actions on the web application.
Recommendations
For Sun Java System Messaging Server versions 6.0 through 6.2, update to a version that includes a fix for this issue.
For iPlanet Messaging Server version 5.2, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting the use of Webmail in these versions to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sun Java System Messaging Server
Iplanet Messaging Server