4.9
CVE-2006-6438
- EPSS 0.31%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:07
- Erkennungen
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), which allows local users to obtain the data by reading the http.log file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xerox ≫ Workcentre 232 Edition pro
Xerox ≫ Workcentre 238 Edition pro
Xerox ≫ Workcentre 245 Edition pro
Xerox ≫ Workcentre 255 Edition pro
Xerox ≫ Workcentre 265 Edition pro
Xerox ≫ Workcentre 275 Edition pro
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.226 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:C/I:N/A:N
|
http://secunia.com/advisories/23265
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf