PT-2006-6201 · Planet+1 · Iplanet Messaging Server+1
Published
2006-10-24
·
Updated
2017-07-20
·
CVE-2006-5486
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Java System Messaging Server versions 6.0 through 6.2
iPlanet Messaging Server version 5.2
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to execute arbitrary Javascript via crafted messages. This could potentially lead to unauthorized actions on the web application.
Recommendations
For Sun Java System Messaging Server versions 6.0 through 6.2, update to a version that includes a fix for this issue.
For iPlanet Messaging Server version 5.2, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting the use of Webmail in these versions to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sun Java System Messaging Server
Iplanet Messaging Server