First published: Thu Apr 07 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login name, which is not filtered when the administrator views the log file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sonicwall Soho Firmware | =5.1.7.0 | |
SonicWALL SOHO |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1006 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To remediate CVE-2005-1006, users should upgrade to a patched version of the SonicWALL SOHO firmware that addresses the XSS vulnerabilities.
CVE-2005-1006 allows attackers to perform cross-site scripting attacks by injecting arbitrary scripts or HTML code.
CVE-2005-1006 specifically affects SonicWALL SOHO firmware version 5.1.7.0.
Yes, remote attackers can exploit CVE-2005-1006 through unfiltered inputs in the URL or user login name.