CVE-2006-6427
Summary
| CVE | CVE-2006-6427 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-10 11:28:00 UTC |
| Updated | 2017-07-29 01:29:00 UTC |
| Description | The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Xerox | Workcentre | 12.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 12.060.17.000 | All | pro | All |
| Hardware | Xerox | Workcentre | 13.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 13.060.17.000 | All | pro | All |
| Hardware | Xerox | Workcentre | 14.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 14.060.17.000 | All | pro | All |
| Hardware | Xerox | Workcentre | 12.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 12.060.17.000 | All | pro | All |
| Hardware | Xerox | Workcentre | 13.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 13.060.17.000 | All | pro | All |
| Hardware | Xerox | Workcentre | 14.060.17.000 | All | All | All |
| Hardware | Xerox | Workcentre | 14.060.17.000 | All | pro | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Xerox WorkCentre and WorkCentre Pro Multiple Vulnerabilities | BID | www.securityfocus.com | |
| www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf | CONFIRM | www.xerox.com | |
| XEROX WorkCentre Products Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Xerox Document Centre Input Validation Flaw in 'hostname' Parameter Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf | CONFIRM | www.xerox.com | Patch |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.