PT-2006-5701 · Sun · Sun Secure Global Desktop
Marc Ruef
·
Published
2006-09-23
·
Updated
2018-10-17
·
CVE-2006-4958
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Secure Global Desktop versions prior to 4.20.983
Description
The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML. The attack vectors are unspecified but possibly involve several CGI and JSP files, including
taarchives.cgi, ttaAuthentication.jsp, ttalicense.cgi, ttawlogin.cgi, ttawebtop.cgi, ttaabout.cgi, and test-cgi.Recommendations
For versions prior to 4.20.983, update to version 4.20.983 or later to resolve the issue. As a temporary workaround, consider restricting access to the potentially vulnerable CGI and JSP files until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Secure Global Desktop