Back to search
CVE-2006-5290
Published: Oct 13, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via "WebUI command injection on TCP/IP hostname."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
22252
third-party-advisory
x_refsource_SECUNIA
20334
vdb-entry
x_refsource_BID
xerox-hostname-command-execution(29357)
vdb-entry
x_refsource_XF
1016981
vdb-entry
x_refsource_SECTRACK
ADV-2006-3921
vdb-entry
x_refsource_VUPEN
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_005.pdf
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now