7.5

CVE-2006-6427

The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration.  NOTE: vector 1 might be the same as CVE-2006-5290.

Data is provided by the National Vulnerability Database (NVD)
XeroxWorkcentre Version12.060.17.000
XeroxWorkcentre Version12.060.17.000 Editionpro
XeroxWorkcentre Version13.060.17.000
XeroxWorkcentre Version13.060.17.000 Editionpro
XeroxWorkcentre Version14.060.17.000
XeroxWorkcentre Version14.060.17.000 Editionpro
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.48% 0.887
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.