CVE-2006-4199
Summary
| CVE | CVE-2006-4199 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-17 21:04:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page, a different vulnerability than CVE-2004-1512. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Soft3304 | 04webserver | 1.42 | All | All | All |
| Application | Soft3304 | 04webserver | 1.5 | All | All | All |
| Application | Soft3304 | 04webserver | 1.81 | All | All | All |
| Application | Soft3304 | 04webserver | 1.42 | All | All | All |
| Application | Soft3304 | 04webserver | 1.5 | All | All | All |
| Application | Soft3304 | 04webserver | 1.81 | All | All | All |
| Application | Soft3304 | 04webserver | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 04WebServer Multiple Vulnerabilities | BID | www.securityfocus.com | Patch |
| www.soft3304.net/04WebServer/Security.html | CONFIRM | www.soft3304.net | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Secunia - Advisories - 04WebServer Cross-Site Scripting and Security Bypass | SECUNIA | secunia.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.