CVE-2006-5741
Last modified
CVE-2006-5741 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in AirMagnet Enterprise before 7.5 build 6307 allow remote attackers to inject arbitrary web script or HTML via (1) the 404 error page of the Smart Sensor Edge Sensor; (2) the user name for a failed logon, when displayed in the audit journals reviewing interface (/AirMagnetSensor/AMSensor.dll/XH) by the Smart Sensor Edge Sensor log viewer; and (3) an SSID of an AP, when displayed on an ACL page (/Amom/Amom.dll/BD) of the Enterprise Server Status Overview in the Enterprise Server Web interface.. EPSS estimates a 1.33% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in AirMagnet Enterprise before 7.5 build 6307 allow remote attackers to inject arbitrary web script or HTML via (1) the 404 error page of the Smart Sensor Edge Sensor; (2) the user name for a failed logon, when displayed in the audit journals reviewing interface (/AirMagnetSensor/AMSensor.dll/XH) by the Smart Sensor Edge Sensor log viewer; and (3) an SSID of an AP, when displayed on an ACL page (/Amom/Amom.dll/BD) of the Enterprise Server Status Overview in the Enterprise Server Web interface.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Airmagnet | Enterprise | 7.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5741?
How severe is CVE-2006-5741?
How do I fix CVE-2006-5741?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-5735Directory traversal vulnerability in include/common.php in P…
- CVE-2006-5736SQL injection vulnerability in search.php in PunBB before 1.…
- CVE-2006-5737PunBB uses a predictable cookie_seed value that can be deriv…
- CVE-2006-5738Multiple SQL injection vulnerabilities in PunBB before 1.2.1…7.2
- CVE-2006-5739PHP remote file inclusion vulnerability in cpadmin/cpa_index…
- CVE-2006-5740Unspecified vulnerability in the LDAP dissector in Wireshark…
- CVE-2006-5742The AirMagnet Enterprise console and Remote Sensor console (…
- CVE-2006-5743Multiple cross-site scripting (XSS) vulnerabilities in Highw…
- CVE-2006-5744Multiple SQL injection vulnerabilities in Highwall Enterpris…
- CVE-2006-5745Unspecified vulnerability in the setRequestHeader method in …
- CVE-2006-5746The console in AirMagnet Enterprise before 7.5 build 6307 do…
- CVE-2006-5747Unspecified vulnerability in Mozilla Firefox before 1.5.0.8,…
Are you affected by CVE-2006-5741?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
