Cross-site Scripting Vulnerability in Sun iPlanet Messaging Server Messenger Express
CVE-2006-5652

Currently unrated

Key Information:

Vendor

Oracle

Vendor
CVE Published:
3 November 2006

What is CVE-2006-5652?

A cross-site scripting (XSS) vulnerability exists in Sun iPlanet Messaging Server Messenger Express, enabling remote attackers to inject arbitrary web scripts. This can occur through the expression Cascading Style Sheets (CSS) function, with potential abuse via setting the width style for an IMG element. This issue is noted for its connection to a related vulnerability, but has been distinctly cataloged due to the differing details provided by various researchers.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2006-5652 : Cross-site Scripting Vulnerability in Sun iPlanet Messaging Server Messenger Express