Show plain JSON{"id": "CVE-2006-5290", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}]}, "published": "2006-10-13T20:07:00.000", "references": [{"url": "http://secunia.com/advisories/22252", "tags": ["Patch", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://securitytracker.com/id?1016981", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/20334/info", "tags": ["Patch"], "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2006/3921", "source": "cve@mitre.org"}, {"url": "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_005.pdf", "tags": ["Patch"], "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29357", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/22252", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securitytracker.com/id?1016981", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/20334/info", "tags": ["Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2006/3921", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_005.pdf", "tags": ["Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29357", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via \"WebUI command injection on TCP/IP hostname.\""}, {"lang": "es", "value": "Los componentes ESS/ Network Controller y MicroServer Web Server de Xerox WorkCentre y WorkCentre Pro 232, 238, 245, 255, 265 y 275 permiten a un atacante remoto evitar la validaci\u00f3n y ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de \"comando de inyecci\u00f3n WebUI sobre el TCP/IP del nomber del host\"."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:xerox:workcentre_232:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24E761E4-0B6C-4C2A-BFCA-4CFC5620E91C"}, {"criteria": "cpe:2.3:h:xerox:workcentre_232:*:*:pro:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "74245D08-446A-4988-BCFD-85509C4CE340"}, {"criteria": "cpe:2.3:h:xerox:workcentre_238:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12790FD1-DECA-4074-9458-3F88823190EF"}, {"criteria": "cpe:2.3:h:xerox:workcentre_238:*:*:pro:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88E2F705-B185-4211-B0CC-1E295E5B4471"}, {"criteria": "cpe:2.3:h:xerox:workcentre_245:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D7FE90B-21E6-4628-AD70-37BB9644CBD9"}, {"criteria": "cpe:2.3:h:xerox:workcentre_245:*:*:pro:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "573640FF-609D-4441-B7DD-3477F239A00E"}, {"criteria": "cpe:2.3:h:xerox:workcentre_255:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8204B5C0-0B87-48BD-9678-5101B048C135"}, {"criteria": "cpe:2.3:h:xerox:workcentre_255:*:*:pro:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A2128EF-5847-4097-84BC-5CAC270F1C10"}, {"criteria": "cpe:2.3:h:xerox:workcentre_265:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BAE44F85-3F9A-45FC-A411-1D1B4C2E33D7"}, {"criteria": "cpe:2.3:h:xerox:workcentre_265:*:*:pro:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8FD8F59-E229-4138-9B85-7E15A80CF5DD"}, {"criteria": "cpe:2.3:h:xerox:workcentre_275:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92119B14-94C5-4D3D-811E-EB7336E39F3E"}, {"criteria": "cpe:2.3:h:xerox:workcentre_275:*:*:pro:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DC671C6-7444-4E3D-ACAB-8905A0DB40CB"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}