CVE-2006-6276
Summary
| CVE | CVE-2006-6276 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-04 11:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Java System Application Server | 7.0 | All | All | All |
| Application | Sun | Java System Application Server | 8.1 | All | All | All |
| Application | Sun | Java System Web Proxy Server | - | All | All | All |
| Application | Sun | Java System Web Proxy Server | 3.6 | All | All | All |
| Application | Sun | Java System Web Proxy Server | 4.0 | All | All | All |
| Application | Sun | Java System Web Server | 6.0 | All | All | All |
| Application | Sun | Java System Web Server | 6.1 | All | All | All |
| Application | Sun | One Application Server | 7.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Sun Java System Web Proxy Server Lets Remote Users Conduct HTTP Request Smuggling Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| #102733: Security Vulnerability With HTTP Requests in Sun Java System Server(s) | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link, Patch |
| SecurityTracker.com Archives - Sun Java Application Server Lets Remote Users Conduct HTTP Request Smuggling Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| SecurityTracker.com Archives - Sun Java System Web Server Lets Remote Users Conduct HTTP Request Smuggling Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Sun Java System Server Products HTTP Request Smuggling - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Sun Multiple Java System Request Smuggling Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Patch, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.