Lucene search

K
cveMitreCVE-2006-2435
HistoryMay 17, 2006 - 10:06 a.m.

CVE-2006-2435

2006-05-1710:06:00
mitre
web.nvd.nist.gov
26
cve-2006-2435
ibm
websphere
application server
vulnerability
script tags
execution of scripts

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.4

Confidence

High

EPSS

0.009

Percentile

82.3%

Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to “Inserting certain script tags in urls [that] may allow unintended execution of scripts.”

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch5.0.0
OR
ibmwebsphere_application_serverMatch5.0.1
OR
ibmwebsphere_application_serverMatch5.0.2
OR
ibmwebsphere_application_serverMatch5.1.0
OR
ibmwebsphere_application_serverMatch5.1.1
VendorProductVersionCPE
ibmwebsphere_application_server5.0.0cpe:2.3:a:ibm:websphere_application_server:5.0.0:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.1cpe:2.3:a:ibm:websphere_application_server:5.0.1:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2cpe:2.3:a:ibm:websphere_application_server:5.0.2:*:*:*:*:*:*:*
ibmwebsphere_application_server5.1.0cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*
ibmwebsphere_application_server5.1.1cpe:2.3:a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.4

Confidence

High

EPSS

0.009

Percentile

82.3%

Related for CVE-2006-2435