First published: Tue Jun 27 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Trend Micro Control Manager (TMCM) 3.5 allows remote attackers to inject arbitrary web script or HTML via the username field on the login page, which is not properly sanitized before being displayed in the error log.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Control Manager | =3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3261 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2006-3261, ensure that input validation and output encoding are properly implemented on the username field.
CVE-2006-3261 affects Trend Micro Control Manager version 3.5.
Successful exploitation of CVE-2006-3261 may allow attackers to inject and execute arbitrary web scripts or HTML.
Details about public exploits for CVE-2006-3261 are not widely documented, but the vulnerability itself is known.