Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/22575 - Vendor Advisory | |
References | () http://securitytracker.com/id?1017113 - | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-26-102497-1 - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/20708 - | |
References | () http://www.vupen.com/english/advisories/2006/4183 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/29806 - |
Information
Published : 2006-10-24 22:07
Updated : 2024-11-21 00:19
NVD link : CVE-2006-5486
Mitre link : CVE-2006-5486
CVE.ORG link : CVE-2006-5486
JSON object : View
Products Affected
sun
- java_system_messaging_server
- iplanet_messaging_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')