| Vulnerability Name: | CVE-2006-3567 (CCN-27645) | ||||||||
| Assigned: | 2006-07-10 | ||||||||
| Published: | 2006-07-10 | ||||||||
| Updated: | 2018-10-18 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: Full-Disclosure Mailing List, Mon Jul 10 2006 - 11:16:09 CDT Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability Source: MITRE Type: CNA CVE-2006-3567 Source: CCN Type: SA20990 Juniper Networks DX System Log Script Insertion Source: SECUNIA Type: Vendor Advisory 20990 Source: SREASON Type: UNKNOWN 1218 Source: CCN Type: SECTRACK ID: 1016462 Juniper DX Application Acceleration Platform Input Validation Hole in Web Interface Permits Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1016462 Source: CCN Type: Juniper Networks Web site DX platforms Source: OSVDB Type: UNKNOWN 27131 Source: CCN Type: OSVDB ID: 27131 Juniper Networks DX System Web Admin Log Script XSS Source: BUGTRAQ Type: UNKNOWN 20060710 Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability Source: BID Type: UNKNOWN 18926 Source: CCN Type: BID-18926 Juniper Networks DX Web Login HTML Injection Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2741 Source: XF Type: UNKNOWN juniper-networks-logging-xss(27645) Source: XF Type: UNKNOWN juniper-networks-logging-xss(27645) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||