First published: Wed Jul 12 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in an error message when trying to access a blocked web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clearswift MIMEsweeper for Web | <=5.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3522 is classified as a medium severity vulnerability due to its potential for exploitation via XSS attacks.
To fix CVE-2006-3522, upgrade to Clearswift MIMEsweeper for Web version 5.1.15 or later where the vulnerability has been addressed.
CVE-2006-3522 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts.
CVE-2006-3522 affects users of Clearswift MIMEsweeper for Web versions prior to 5.1.15 Hotfix.
Attackers exploiting CVE-2006-3522 can inject and execute malicious scripts in the context of a user accessing a blocked website.