First published: Sun Mar 26 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University Of Washington Pubcookie | =3.3.0 | |
University Of Washington Pubcookie | =3.2.0 | |
University Of Washington Pubcookie | =3.2.1a | |
University Of Washington Pubcookie | =3.1.0 | |
University Of Washington Pubcookie | =3.0.0 | |
University Of Washington Pubcookie | =3.1.1 | |
University Of Washington Pubcookie | =3.2.1 | |
University of Washington Pubcookie | =3.0.0 | |
University of Washington Pubcookie | =3.1.0 | |
University of Washington Pubcookie | =3.1.1 | |
University of Washington Pubcookie | =3.2.0 | |
University of Washington Pubcookie | =3.2.1 | |
University of Washington Pubcookie | =3.2.1a | |
University of Washington Pubcookie | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1394 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-1394, upgrade the University of Washington Pubcookie to version 3.2.1b or later.
CVE-2006-1394 affects Pubcookie versions 3.1.0, 3.1.1, 3.2.0, 3.2.1a, and 3.3 prior to 3.3.0a.
CVE-2006-1394 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts.
Users of the University of Washington Pubcookie application server module versions listed in the vulnerability are at risk.