PT-2006-6201 · Planet+1 · Iplanet Messaging Server+1

Published

2006-10-24

·

Updated

2017-07-20

·

CVE-2006-5486

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sun Java System Messaging Server versions 6.0 through 6.2 iPlanet Messaging Server version 5.2
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to execute arbitrary Javascript via crafted messages. This could potentially lead to unauthorized actions on the web application.
Recommendations For Sun Java System Messaging Server versions 6.0 through 6.2, update to a version that includes a fix for this issue. For iPlanet Messaging Server version 5.2, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting the use of Webmail in these versions to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-5486

Affected Products

Sun Java System Messaging Server
Iplanet Messaging Server