CVE-2006-3522
 
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in an error message when trying to access a blocked web site.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Clearswift MIMEsweeper for Web versiones anteriores a 5.1.15 Hotfix, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de la URL, se ve reflejado en un mensaje de error cuando se intenta acceder a un sitio web bloqueado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-07-11 CVE Reserved
- 2006-07-12 CVE Published
- 2023-09-06 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=full-disclosure&m=115249298204354&w=2 | Mailing List | |
http://marc.info/?l=full-disclosure&m=115253320721404&w=2 | Mailing List | |
http://marc.info/?l=full-disclosure&m=115253898206225&w=2 | Mailing List | |
http://securitytracker.com/id?1016454 | Vdb Entry | |
http://www.securityfocus.com/archive/1/439641/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/440140/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/18916 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/2731 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27642 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://download.mimesweeper.com/www/TechnicalDocumentation/WebReadMeHotfix5115.htm | 2018-10-18 | |
http://secunia.com/advisories/20998 | 2018-10-18 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Clearswift Search vendor "Clearswift" | Mimesweeper For Web Search vendor "Clearswift" for product "Mimesweeper For Web" | <= 5.1.14 Search vendor "Clearswift" for product "Mimesweeper For Web" and version " <= 5.1.14" | - |
Affected
|