CVE-2006-5036
Last modified
CVE-2006-5036 is a vulnerability of currently unknown severity. MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squiz | Mysource Classic | <= 2.16.2 |
| Squiz | Mysource Matrix | <= 3.8 |
References
- http://www.aushack.com/advisories/200607-mysourcematrix.txtVendor Advisory
- http://www.aushack.com/advisories/200607-mysourcematrix.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5036?
How severe is CVE-2006-5036?
How do I fix CVE-2006-5036?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-5030SQL injection vulnerability in modules/messages/index.php in…
- CVE-2006-5031Directory traversal vulnerability in app/webroot/js/vendors.…
- CVE-2006-5032PHP remote file inclusion vulnerability in dix.php3 in PHPar…
- CVE-2006-5033Unspecified vulnerability in StoresAndCalendarsList.cgi in P…
- CVE-2006-5034Directory traversal vulnerability in Paul Smith Computer Ser…
- CVE-2006-5035Multiple cross-site scripting (XSS) vulnerabilities in Paul …
- CVE-2006-5037MySource Matrix after 3.8 allows remote attackers to use the…
- CVE-2006-5038The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version …
- CVE-2006-5039Unspecified vulnerability in Events 1.3 beta module (com_eve…
- CVE-2006-5040Unspecified vulnerability in SEF404x (com_sef) for Joomla! h…
- CVE-2006-5041Unspecified vulnerability in Hot Properties (possibly com_ho…
- CVE-2006-5042Unspecified vulnerability in mosMedia (com_mosmedia) 1.0.8 a…
Are you affected by CVE-2006-5036?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
