CVE-2006-6436
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML via HTTP TRACE messages.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el controlador de red de Xerox WorkCentre and WorkCentre Pro anteriores a 12.050.03.000, 13.x anteriores a 13.050.03.000, y 14.x anteriores a 14.050.03.000 permite a atacantes remotos inyectar scripts web o HTML de su elección mediante mensajes HTTP TRACE.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-12-09 CVE Reserved
- 2006-12-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/23265 | 2008-09-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xerox Search vendor "Xerox" | Workcentre 232 Search vendor "Xerox" for product "Workcentre 232" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 232 Search vendor "Xerox" for product "Workcentre 232" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 238 Search vendor "Xerox" for product "Workcentre 238" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 238 Search vendor "Xerox" for product "Workcentre 238" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 245 Search vendor "Xerox" for product "Workcentre 245" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 245 Search vendor "Xerox" for product "Workcentre 245" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 255 Search vendor "Xerox" for product "Workcentre 255" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 255 Search vendor "Xerox" for product "Workcentre 255" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 265 Search vendor "Xerox" for product "Workcentre 265" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 265 Search vendor "Xerox" for product "Workcentre 265" | * | pro |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 275 Search vendor "Xerox" for product "Workcentre 275" | * | - |
Affected
| ||||||
Xerox Search vendor "Xerox" | Workcentre 275 Search vendor "Xerox" for product "Workcentre 275" | * | pro |
Affected
|