Lucene search

K
cveMitreCVE-2006-4958
HistorySep 23, 2006 - 10:07 a.m.

CVE-2006-4958

2006-09-2310:07:00
mitre
web.nvd.nist.gov
51
4
cve-2006-4958
cross-site scripting
xss
sun secure global desktop
ssgd
tarantella
remote attackers
arbitrary script
html
security vulnerability
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

High

EPSS

0.071

Percentile

94.0%

Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This information is based upon a vague initial disclosure. Details will be updated as they become available.

Affected configurations

Nvd
Node
sunsecure_global_desktopMatch3.42enterprise
OR
sunsecure_global_desktopMatch4.0enterprise
VendorProductVersionCPE
sunsecure_global_desktop3.42cpe:2.3:a:sun:secure_global_desktop:3.42:*:enterprise:*:*:*:*:*
sunsecure_global_desktop4.0cpe:2.3:a:sun:secure_global_desktop:4.0:*:enterprise:*:*:*:*:*

Social References

More

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

High

EPSS

0.071

Percentile

94.0%

Related for CVE-2006-4958