CVE-2004-0606: XSS
Published Jun 30, 2004
·Updated
Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.
Affected Software
2 affected components
Infoblox Dns One Appliance=2.4.0.8a
Infoblox Dns One Appliance=2.4.0.8
Event History
Jun 30, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0606?
CVE-2004-0606 is considered a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS).
2
How do I fix CVE-2004-0606?
To fix CVE-2004-0606, upgrade Infoblox DNS One firmware to a version later than 2.4.0-8.
3
What are the affected versions of Infoblox DNS One in CVE-2004-0606?
CVE-2004-0606 affects versions 2.4.0-8 and earlier of Infoblox DNS One.
4
What type of vulnerability is CVE-2004-0606?
CVE-2004-0606 is a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2004-0606 allow remote access to systems?
CVE-2004-0606 allows remote attackers to execute arbitrary scripts, which can lead to unauthorized access to user sessions.