CVE-2006-6436: XSS
Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML via HTTP TRACE messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6436?
CVE-2006-6436 is classified as a medium severity Cross-site Scripting (XSS) vulnerability.
How can I fix CVE-2006-6436?
To mitigate CVE-2006-6436, update your Xerox WorkCentre device to version 12.050.03.000 or higher for the affected models.
What devices are affected by CVE-2006-6436?
CVE-2006-6436 affects various models of Xerox WorkCentre and WorkCentre Pro printers prior to specific firmware versions.
What kind of attack can exploit CVE-2006-6436?
CVE-2006-6436 allows remote attackers to inject arbitrary web scripts or HTML via HTTP TRACE messages.
Is there any workaround for CVE-2006-6436?
While the best approach is to update the firmware, disabling the HTTP TRACE method may serve as a temporary workaround for CVE-2006-6436.