CVE-2006-6427
Summary
| CVE | CVE-2006-6427 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-10 11:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Xerox | Workcentre | 12.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 12.060.17.000 | All | pro | All |
| Hardware | Xerox | Workcentre | 13.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 13.060.17.000 | All | pro | All |
| Hardware | Xerox | Workcentre | 14.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 14.060.17.000 | All | pro | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Xerox Document Centre Input Validation Flaw in 'hostname' Parameter Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Vendor Advisory |
| www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.xerox.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| XEROX WorkCentre Products Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.xerox.com | |
| Xerox WorkCentre and WorkCentre Pro Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.