CVE-2006-5290
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via "WebUI command injection on TCP/IP hostname."
Los componentes ESS/ Network Controller y MicroServer Web Server de Xerox WorkCentre y WorkCentre Pro 232, 238, 245, 255, 265 y 275 permiten a un atacante remoto evitar la validación y ejecutar código de su elección a través de "comando de inyección WebUI sobre el TCP/IP del nomber del host".
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-10-13 CVE Reserved
- 2006-10-13 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1016981 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/3921 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29357 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/22252 | 2017-07-20 | |
http://www.securityfocus.com/bid/20334/info | 2017-07-20 | |
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_005.pdf | 2017-07-20 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xerox Search vendor "Xerox" | Workcentre 232 Search vendor "Xerox" for product "Workcentre 232" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 232 Search vendor "Xerox" for product "Workcentre 232" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 238 Search vendor "Xerox" for product "Workcentre 238" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 238 Search vendor "Xerox" for product "Workcentre 238" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 245 Search vendor "Xerox" for product "Workcentre 245" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 245 Search vendor "Xerox" for product "Workcentre 245" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 255 Search vendor "Xerox" for product "Workcentre 255" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 255 Search vendor "Xerox" for product "Workcentre 255" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 265 Search vendor "Xerox" for product "Workcentre 265" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 265 Search vendor "Xerox" for product "Workcentre 265" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 275 Search vendor "Xerox" for product "Workcentre 275" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 275 Search vendor "Xerox" for product "Workcentre 275" | * | pro |
Affected
|