1 results (0.009 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 3

Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned. Vulnerabilidad de cruce de sitios en scripts (XSS) en la función errorHTML en el script índice en Sun Java System Messenger Express 6 permite a atacantes remotos inyectar scripts WEB o HTML de su elección mediante el parámetro error. NOTA: Esta vulnerabilidad podría estar en relación con CVE-2006-5486, sin embargo debido a la ligereza de la notificación inicial y a diferentes investigadores, se le ha asignado un nuevo CVE. • https://www.exploit-db.com/exploits/28887 http://secunia.com/advisories/22663 http://securityreason.com/securityalert/1805 http://www.securityfocus.com/archive/1/450153/100/0/threaded http://www.securityfocus.com/archive/1/456273/100/200/threaded http://www.securityfocus.com/bid/20832 http://www.securitytracker.com/id?1018106 http://www.vupen.com/english/advisories/2006/4281 https://exchange.xforce.ibmcloud.com/vulnerabilities/29939 •