CVE-2006-2351
Summary
| CVE | CVE-2006-2351 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-15 10:02:00 UTC |
| Updated | 2017-07-20 01:31:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ipswitch | Whatsup Professional | 2006 | All | All | All |
| Application | Ipswitch | Whatsup Professional | 2006_premium | All | All | All |
| Application | Ipswitch | Whatsup Professional | 2006 | All | All | All |
| Application | Ipswitch | Whatsup Professional | 2006_premium | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 25470 | OSVDB | www.osvdb.org | |
| WhatsUp Professional Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Vendor Advisory |
| Ipswitch WhatsUp Professional Multiple Input Validation Vulnerabilities | BID | www.securityfocus.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | Exploit, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Ipswitch WhatsUp Professional multiple flaws - CXSecurity.com | SREASON | securityreason.com | |
| 25469 | OSVDB | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.