VYPR
Unrated severityNVD Advisory· Published May 15, 2006· Updated Apr 16, 2026

CVE-2006-2351

CVE-2006-2351

Description

Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.

Affected products

2
  • cpe:2.3:a:ipswitch:whatsup_professional:2006:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ipswitch:whatsup_professional:2006:*:*:*:*:*:*:*
    • cpe:2.3:a:ipswitch:whatsup_professional:2006_premium:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.