MEDIUM · 6.8

CVE-2006-5036

MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server'...

Vulnerability Description

MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SquizMysource Classic<= 2.16.2
SquizMysource Matrix<= 3.8

References

FAQ

What is CVE-2006-5036?

CVE-2006-5036 is a vulnerability with a CVSS score of 6.8 (MEDIUM). MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server'...

How severe is CVE-2006-5036?

CVE-2006-5036 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-5036?

Check the references section above for vendor advisories and patch information. Affected products include: Squiz Mysource Classic, Squiz Mysource Matrix.