CVE Database
/

CVE-2006-6427

Back to search

CVE-2006-6427

Published: Dec 10, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290.

VendorProductVersions

n/a

n/a

affected
n/a

References

1017337
vdb-entry
x_refsource_SECTRACK
xerox-webui-code-execution(30674)
vdb-entry
x_refsource_XF
23265
third-party-advisory
x_refsource_SECUNIA
21365
vdb-entry
x_refsource_BID
ADV-2006-4791
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now