CVE-2006-3522 Information

Description

Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to inject arbitrary web script or HTML via the URL which is reflected back in an error message when trying to access a blocked web site.

Reference

http://download.mimesweeper.com/www/TechnicalDocumentation/WebReadMeHotfix5115.htm http://marc.info/?l=full-disclosure&m=115249298204354&w=2 http://marc.info/?l=full-disclosure&m=115253320721404&w=2 http://marc.info/?l=full-disclosure&m=115253898206225&w=2 http://secunia.com/advisories/20998 http://securitytracker.com/id?1016454 http://www.securityfocus.com/archive/1/439641/100/0/threaded http://www.securityfocus.com/archive/1/440140/100/0/threaded http://www.securityfocus.com/bid/18916 http://www.vupen.com/english/advisories/2006/2731 https://exchange.xforce.ibmcloud.com/vulnerabilities/27642

Share on: