CVE-2006-4964: XSS
Published Sep 23, 2006
·Updated
Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecified vectors related to the AntiCracker.
Affected Software
4 affected components
MAXdev MD-Pro<=1.0.76
MAXdev MD-Pro=1.0.72
MAXdev MD-Pro=1.0.73
MAXdev MD-Pro=1.0.75
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 23, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4964?
CVE-2006-4964 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
Which versions of MAXdev MDPro are affected by CVE-2006-4964?
CVE-2006-4964 affects MAXdev MDPro versions up to 1.0.76 before the version released on 20060918.
3
How do I fix CVE-2006-4964?
To fix CVE-2006-4964, upgrade to MAXdev MDPro version 1.0.76 or later.
4
Can CVE-2006-4964 be exploited by remote attackers?
Yes, CVE-2006-4964 can be exploited by remote attackers to inject arbitrary web scripts or HTML.
5
What mechanisms are bypassed in CVE-2006-4964?
CVE-2006-4964 bypasses the XSS protection mechanisms of the pnVarCleanFromInput function.