← back
CVE-2006-5652

CVE-2006-5652

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.7%
from disclosure to weapon0 days
Published on NVDNov 3
1st PoCOct 31
exploitation probability
1.7%top 26% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.