First published: Sat Sep 23 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This information is based upon a vague initial disclosure. Details will be updated as they become available.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tarantella Secure Global Desktop | =4.0 | |
Tarantella Secure Global Desktop | =3.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4958 is classified with a moderate severity due to its potential for cross-site scripting attacks.
To fix CVE-2006-4958, update your Sun Secure Global Desktop to the latest version where the vulnerabilities have been patched.
CVE-2006-4958 encompasses multiple cross-site scripting (XSS) vulnerabilities that allow for arbitrary web script injections.
CVE-2006-4958 affects Sun Secure Global Desktop versions 3.42 and 4.0.
CVE-2006-4958 can be exploited by remote attackers who can inject malicious scripts into the application.