{"api_version":"1","generated_at":"2026-04-23T09:52:04+00:00","cve":"CVE-2006-3567","urls":{"html":"https://cve.report/CVE-2006-3567","api":"https://cve.report/api/cve/CVE-2006-3567.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3567","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3567"},"summary":{"title":"CVE-2006-3567","description":"Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-07-13 01:05:00","updated_at":"2018-10-18 16:48:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://secunia.com/advisories/20990","name":"20990","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Juniper Networks DX System Log Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2741","name":"ADV-2006-2741","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/439758/100/0/threaded","name":"20060710 Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/18926","name":"18926","refsource":"BID","tags":[],"title":"Juniper Networks DX Web Login HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/27131","name":"27131","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/1218","name":"1218","refsource":"SREASON","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27645","name":"juniper-networks-logging-xss(27645)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016462","name":"1016462","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Juniper DX Application Acceleration Platform Input Validation Hole in Web Interface Permits Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3567","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3567","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3567","vulnerable":"1","versionEndIncluding":"5.1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"juniper","cpe5":"dx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3567","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1016462","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016462"},{"name":"ADV-2006-2741","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2741"},{"name":"1218","refsource":"SREASON","url":"http://securityreason.com/securityalert/1218"},{"name":"20060710 Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/439758/100/0/threaded"},{"name":"18926","refsource":"BID","url":"http://www.securityfocus.com/bid/18926"},{"name":"27131","refsource":"OSVDB","url":"http://www.osvdb.org/27131"},{"name":"juniper-networks-logging-xss(27645)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27645"},{"name":"20990","refsource":"SECUNIA","url":"http://secunia.com/advisories/20990"}]}},"nvd":{"publishedDate":"2006-07-13 01:05:00","lastModifiedDate":"2018-10-18 16:48:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:h:juniper:dx:*:*:*:*:*:*:*:*","versionEndIncluding":"5.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3567","Ordinal":"18893","Title":"CVE-2006-3567","CVE":"CVE-2006-3567","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3567","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3567","Ordinal":"2","NoteData":"2006-07-12","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3567","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}