CVE-2006-5290: Command Injection
The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via "WebUI command injection on TCP/IP hostname."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5290?
CVE-2006-5290 is considered to have a critical severity level due to its ability to allow remote code execution.
How do I fix CVE-2006-5290?
To fix CVE-2006-5290, you should apply the latest firmware updates provided by Xerox for the affected WorkCentre models.
Which Xerox products are affected by CVE-2006-5290?
CVE-2006-5290 affects several models including Xerox WorkCentre 232, 238, 245, 255, 265, and 275.
What type of attack does CVE-2006-5290 enable?
CVE-2006-5290 enables attackers to bypass authentication and execute arbitrary code remotely.
Is CVE-2006-5290 a network vulnerability?
Yes, CVE-2006-5290 is a network vulnerability that exploits weaknesses in the web server components of affected Xerox devices.