Cross-site Scripting Vulnerability in Sun Java System Messaging Server
CVE-2006-5486 
Currently unrated
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 24 October 2006
What is CVE-2006-5486?
A cross-site scripting (XSS) vulnerability exists in the Webmail component of the Sun Java System Messaging Server and the iPlanet Messaging Server. This flaw permits remote attackers to inject and execute arbitrary JavaScript code through specially crafted email messages. Effective exploitation can lead to unauthorized actions being performed on behalf of users, potentially jeopardizing sensitive data and compromising the integrity of session tokens.