First published: Mon Oct 02 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command parameter, different vectors than CVE-2003-0749.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Internet Transaction Server | =6.2 | |
SAP Internet Transaction Server | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5114 is classified as a high severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2006-5114, update your SAP Internet Transaction Server to either version 6.1 or 6.2 with the latest security patches.
CVE-2006-5114 affects SAP Internet Transaction Server versions 6.1 and 6.2.
CVE-2006-5114 enables remote attackers to perform cross-site scripting attacks, allowing arbitrary web script or HTML injection.
Yes, CVE-2006-5114 is a known vulnerability publicly documented in various security advisories.