CVE-2006-3522
Summary
| CVE | CVE-2006-3522 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-12 00:05:00 UTC |
| Updated | 2018-10-18 16:47:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in an error message when trying to access a blocked web site. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Clearswift | Mimesweeper For Web | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| MIMESweeper For Web Access Denied Cross-site Scripting Vulnerability | BID | www.securityfocus.com | |
| download.mimesweeper.com/www/TechnicalDocumentation/WebReadMeHotfix5115.htm | CONFIRM | download.mimesweeper.com | Patch |
| 'Re: [Full-disclosure] MIMESweeper For Web 5.X Cross Site Scripting' - MARC | FULLDISC | marc.info | |
| SecurityTracker.com Archives - MIMEsweeper for Web Input Validation Hole in 'Access Denied' Page Permits Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| '[Full-disclosure] RE: MIMESweeper For Web 5.X Cross Site Scripting' - MARC | FULLDISC | marc.info | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| '[Full-disclosure] MIMESweeper For Web 5.X Cross Site Scripting' - MARC | FULLDISC | marc.info | |
| Secunia - Advisories - MIMEsweeper for Web Cross-Site Scripting and Denial of Service | SECUNIA | secunia.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.