CVE-2006-3261
Summary
| CVE | CVE-2006-3261 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-27 21:05:00 UTC |
| Updated | 2018-10-18 16:46:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Trend Micro Control Manager (TMCM) 3.5 allows remote attackers to inject arbitrary web script or HTML via the username field on the login page, which is not properly sanitized before being displayed in the error log. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trend Micro | Control Manager | 3.5 | All | All | All |
| Application | Trend Micro | Control Manager | 3.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Trend Micro Control Manager Access Log HTML Injection Vulnerability | BID | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - Trend Micro Control Manager Input Validation Hole Permits Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | |
| SecurityReason - Trend Micro Control Manager (TMCM) Persistent XSS Vulnerability | SREASON | securityreason.com | |
| Trend Micro Control Manager "Username" Script Insertion - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.