6.8
CVE-2006-6436
- EPSS 1.09%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:07
- Erkennungen
Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML via HTTP TRACE messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xerox ≫ Workcentre 232 Edition pro
Xerox ≫ Workcentre 238 Edition pro
Xerox ≫ Workcentre 245 Edition pro
Xerox ≫ Workcentre 255 Edition pro
Xerox ≫ Workcentre 265 Edition pro
Xerox ≫ Workcentre 275 Edition pro
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.09% | 0.613 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/23265
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf