CVE-2006-1394: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1394?
CVE-2006-1394 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-1394?
To fix CVE-2006-1394, upgrade the University of Washington Pubcookie to version 3.2.1b or later.
Which versions of Pubcookie are affected by CVE-2006-1394?
CVE-2006-1394 affects Pubcookie versions 3.1.0, 3.1.1, 3.2.0, 3.2.1a, and 3.3 prior to 3.3.0a.
What types of attacks can CVE-2006-1394 facilitate?
CVE-2006-1394 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts.
Who is impacted by CVE-2006-1394?
Users of the University of Washington Pubcookie application server module versions listed in the vulnerability are at risk.