CVE-2006-4958
Summary
| CVE | CVE-2006-4958 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-23 10:07:00 UTC |
| Updated | 2018-10-17 21:40:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This information is based upon a vague initial disclosure. Details will be updated as they become available. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Secure Global Desktop | 3.42 | All | enterprise | All |
| Application | Sun | Secure Global Desktop | 4.0 | All | enterprise | All |
| Application | Sun | Secure Global Desktop | 3.42 | All | enterprise | All |
| Application | Sun | Secure Global Desktop | 4.0 | All | enterprise | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Sun Secure Global Desktop Input Validation Holes Permit Cross-Site Scripting Attacks and Disclose System Information to Remote Users | SECTRACK | securitytracker.com | |
| scip AG [Security - Consulting - Information - Process] | MISC | www.scip.ch | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Sun Secure Global Desktop Unspecified Multiple Input Validation Vulnerabilities | BID | www.securityfocus.com | |
| Sun Secure Global Desktop Cross-Site Scripting Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| #102650: Cross-site Scripting Vulnerabilities in the Sun Secure Global Desktop Software | SUNALERT | sunsolve.sun.com | |
| ASA-2006-235 (SUN 102144, 102510, 102563, 102568, 102650) | CONFIRM | support.avaya.com | |
| SecurityReason - Sun Secure Global Desktop prior 4.3 multiple remote vulnerabilities | SREASON | securityreason.com | |
| Sun Secure Global Desktop Multiple Unspecified Cross-Site Scripting Vulnerabilities | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.