CVE-2006-2925: XSS
Cross-site scripting (XSS) vulnerability in the web interface in Ingate Firewall before 4.4.1 and SIParator before 4.4.1 allows remote attackers to inject arbitrary web script or HTML, and steal cookies, via unspecified vectors related to "XSS exploits" in administrator functionality.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2925?
CVE-2006-2925 is classified as a moderate severity vulnerability due to its potential to enable cross-site scripting attacks.
How do I fix CVE-2006-2925?
To mitigate CVE-2006-2925, upgrade Ingate Firewall and SIParator to version 4.4.1 or later.
What types of attacks can CVE-2006-2925 enable?
CVE-2006-2925 can allow remote attackers to inject arbitrary web scripts or HTML, potentially stealing user cookies.
Which Ingate products are affected by CVE-2006-2925?
CVE-2006-2925 affects Ingate Firewall versions prior to 4.4.1 and SIParator versions prior to 4.4.1.
Are earlier versions of Ingate Firewall and SIParator vulnerable to CVE-2006-2925?
Yes, versions 4.3.1 and earlier of both Ingate Firewall and SIParator are vulnerable to CVE-2006-2925.