CVE-2006-4843: XSS
Published Mar 29, 2007
·Updated
Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protection scheme.
Affected Software
13 affected components
IBM Lotus Domino=6.5.4
IBM Lotus Domino=6.5.2
IBM Lotus Domino=6.5.4
IBM Lotus Domino=6.5.1
IBM Lotus Domino=7.0
IBM Lotus Domino=6.5.0
IBM Lotus Domino=6.5.4
IBM Lotus Domino=6.5.5
IBM Lotus Domino=6.5.3
IBM Lotus Domino=7.0.2
IBM Lotus Domino=6.5.5
IBM Lotus Domino=6.5.5
IBM Lotus Domino=7.0.1
Event History
Mar 29, 2007
CVE Published
09:19 PM
Mar 30, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4843?
CVE-2006-4843 has a moderate severity rating due to its potential for XSS attacks.
2
How do I fix CVE-2006-4843?
To fix CVE-2006-4843, upgrade IBM Lotus Domino to version 6.5.6 or 7.0.2 FP1 or later.
3
What systems are affected by CVE-2006-4843?
CVE-2006-4843 affects specific versions of IBM Lotus Domino including 6.0.x, 6.5.x, and 7.0.x prior to their respective patches.
4
Can CVE-2006-4843 lead to data theft?
Yes, exploitation of CVE-2006-4843 can allow attackers to execute scripts that may lead to data theft from users.
5
What type of vulnerability is CVE-2006-4843?
CVE-2006-4843 is classified as a cross-site scripting (XSS) vulnerability.