CVE-2006-5036
Last modified
CVE-2006-5036 is a vulnerability of currently unknown severity. MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squiz | Mysource Classic | <= 2.16.2 |
| Squiz | Mysource Matrix | <= 3.8 |
References
- http://www.aushack.com/advisories/200607-mysourcematrix.txtVendor Advisory
- http://www.aushack.com/advisories/200607-mysourcematrix.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5036?
How severe is CVE-2006-5036?
How do I fix CVE-2006-5036?
Are you affected by CVE-2006-5036?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
