CVE-2006-2925
Summary
| CVE | CVE-2006-2925 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-09 10:02:00 UTC |
| Updated | 2017-07-20 01:31:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the web interface in Ingate Firewall before 4.4.1 and SIParator before 4.4.1 allows remote attackers to inject arbitrary web script or HTML, and steal cookies, via unspecified vectors related to "XSS exploits" in administrator functionality. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ingate | Ingate Firewall | 4.3.1 | All | All | All |
| Hardware | Ingate | Ingate Firewall | 4.3.1 | All | All | All |
| Hardware | Ingate | Ingate Firewall | All | All | All | All |
| Hardware | Ingate | Siparator | 4.3.1 | All | All | All |
| Hardware | Ingate | Siparator | 4.3.1 | All | All | All |
| Hardware | Ingate | Siparator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release notice for Ingate Firewall® 4.4.1 and Ingate SIParator® 4.4.1 | CONFIRM | www.ingate.com | Patch |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Secunia - Advisories - Ingate Firewall and SIParator Two Vulnerabilities | SECUNIA | secunia.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Ingate Firewall Bugs Let Remote Users Deny Service and Conduct Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - Ingate SIParator Bugs Let Remote Users Deny Service and Conduct Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.