{"api_version":"1","generated_at":"2026-07-24T20:33:28+00:00","cve":"CVE-2006-6427","urls":{"html":"https://cve.report/CVE-2006-6427","api":"https://cve.report/api/cve/CVE-2006-6427.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6427","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6427"},"summary":{"title":"CVE-2006-6427","description":"The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving \"command injection\" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration.  NOTE: vector 1 might be the same as CVE-2006-5290.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-10 11:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-78","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1017337","name":"http://securitytracker.com/id?1017337","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Xerox Document Centre Input Validation Flaw in 'hostname' Parameter Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf","name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4791","name":"http://www.vupen.com/english/advisories/2006/4791","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23265","name":"http://secunia.com/advisories/23265","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"XEROX WorkCentre Products Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf","name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21365","name":"http://www.securityfocus.com/bid/21365","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xerox WorkCentre and WorkCentre Pro Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30674","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30674","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6427","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6427","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6427","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre","cpe6":"12.060.17.000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6427","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre","cpe6":"12.060.17.000","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6427","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre","cpe6":"13.060.17.000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6427","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre","cpe6":"13.060.17.000","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6427","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre","cpe6":"14.060.17.000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6427","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre","cpe6":"14.060.17.000","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:26:46.295Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf"},{"name":"1017337","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017337"},{"name":"xerox-webui-code-execution(30674)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30674"},{"name":"23265","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23265"},{"name":"21365","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21365"},{"name":"ADV-2006-4791","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4791"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving \"command injection\" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration.  NOTE: vector 1 might be the same as CVE-2006-5290."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf"},{"name":"1017337","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017337"},{"name":"xerox-webui-code-execution(30674)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30674"},{"name":"23265","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23265"},{"name":"21365","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21365"},{"name":"ADV-2006-4791","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4791"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6427","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving \"command injection\" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration.  NOTE: vector 1 might be the same as CVE-2006-5290."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf","refsource":"CONFIRM","url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf"},{"name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf","refsource":"CONFIRM","url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_007_v1.pdf"},{"name":"1017337","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017337"},{"name":"xerox-webui-code-execution(30674)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30674"},{"name":"23265","refsource":"SECUNIA","url":"http://secunia.com/advisories/23265"},{"name":"21365","refsource":"BID","url":"http://www.securityfocus.com/bid/21365"},{"name":"ADV-2006-4791","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4791"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6427","datePublished":"2006-12-10T11:00:00.000Z","dateReserved":"2006-12-09T00:00:00.000Z","dateUpdated":"2024-08-07T20:26:46.295Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-10 11:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-78","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre:12.060.17.000:*:*:*:*:*:*:*","matchCriteriaId":"BF9C033D-37D1-445F-B0FC-5B388805506D"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre:12.060.17.000:*:pro:*:*:*:*:*","matchCriteriaId":"216F3E75-F438-4090-980E-E8E4895B7CA0"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre:13.060.17.000:*:*:*:*:*:*:*","matchCriteriaId":"FA3716B1-3B5F-44A5-A5A2-ADA965536D02"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre:13.060.17.000:*:pro:*:*:*:*:*","matchCriteriaId":"4A2E5932-2D90-48C2-93F7-D3040F872E35"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre:14.060.17.000:*:*:*:*:*:*:*","matchCriteriaId":"BEFAD4E9-11AC-425D-A95C-9C722177A51C"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre:14.060.17.000:*:pro:*:*:*:*:*","matchCriteriaId":"5EF56EDD-26FE-405B-9BAA-E5279E46FD32"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6427","Ordinal":"1","Title":"CVE-2006-6427","CVE":"CVE-2006-6427","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6427","Ordinal":"1","NoteData":"The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving \"command injection\" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration.  NOTE: vector 1 might be the same as CVE-2006-5290.","Type":"Description","Title":"CVE-2006-6427"},{"CveYear":"2006","CveId":"6427","Ordinal":"2","NoteData":"2006-12-10","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6427","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}