CVE-2006-6815: XSS
Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to (1) setpreferences.asp, (2) sendpasswordpreferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6815?
CVE-2006-6815 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-6815?
To fix CVE-2006-6815, implement input validation and output encoding on parameters in the affected scripts to prevent XSS.
Who is affected by CVE-2006-6815?
Administrators using DMXReady Secure Login Manager version 1.0 are affected by CVE-2006-6815.
What are the consequences of CVE-2006-6815?
Exploitation of CVE-2006-6815 can allow attackers to inject and execute arbitrary web scripts within the context of affected users.
Can CVE-2006-6815 be exploited remotely?
Yes, CVE-2006-6815 can be exploited remotely by authenticated administrators who have access to the affected parameters.