CVE-2006-5652
Estado: ModificadaMedia (4.3)—
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.68%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050460.html
- http://securityreason.com/securityalert/1806
- http://www.securityfocus.com/archive/1/450184/100/0/threaded
- http://www.securityfocus.com/bid/20838
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29929
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050460.html
- http://securityreason.com/securityalert/1806
- http://www.securityfocus.com/archive/1/450184/100/0/threaded
- http://www.securityfocus.com/bid/20838
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29929
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-5652",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-03T00:07:00.000",
"references": [
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050460.html",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1806",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/450184/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20838",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29929",
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050460.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1806",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/450184/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20838",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29929",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE."
},
{
"lang": "es",
"value": "Vulnerabilidad de cruce de sitios en scripts (XSS) en Sun iPlanet Messaging Server Messenger Express permite a atacantes remotos inyectar scripts WEB de su elección mediante el la expresión de la función CSS (Cascading Style Sheets), como se demuestra fijando el estilo anchura (width) para un elemento IMG.\r\nNOTA: Esta vulnerabilidad podría estar en relación con CVE-2006-5486, sin embargo debido a la ligereza de las notificaciones iniciales, y a diferentes investigadores, se le ha asignado un nuevo CVE.\r\n\r\n"
}
],
"lastModified": "2026-06-16T22:31:36.767",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sun:iplanet_messaging_server_messenger_express:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0C0621B-826C-40C1-AB7F-72F7F9117090"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}