Vulnerability Name: | CVE-2006-2351 (CCN-26500) | ||||||||
Assigned: | 2006-05-11 | ||||||||
Published: | 2006-05-11 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Thu May 11 2006 - 17:06:51 CDT Ipswitch WhatsUp Professional multiple flaws Source: MITRE Type: CNA CVE-2006-2351 Source: CCN Type: SA20075 WhatsUp Professional Multiple Vulnerabilities Source: SECUNIA Type: Exploit, Vendor Advisory 20075 Source: SREASON Type: UNKNOWN 897 Source: CCN Type: Ipswitch, Inc. Web site WhatsUp Professional 2006 - Premium vs. Standard Source: OSVDB Type: UNKNOWN 25469 Source: OSVDB Type: UNKNOWN 25470 Source: CCN Type: OSVDB ID: 25469 Ipswitch WhatsUp Professional NmConsole/Navigation.asp sDeviceView Parameter XSS Source: CCN Type: OSVDB ID: 25470 Ipswitch WhatsUp Professional NmConsole/ToolResults.asp sHostname Parameter XSS Source: BUGTRAQ Type: Exploit, Vendor Advisory 20060511 Ipswitch WhatsUp Professional multiple flaws Source: BID Type: Exploit 17964 Source: CCN Type: BID-17964 Ipswitch WhatsUp Professional Multiple Input Validation Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2006-1787 Source: XF Type: UNKNOWN whatsup-navigation-toolresults-xss(26500) Source: XF Type: UNKNOWN whatsup-navigation-toolresults-xss(26500) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |