Unrated severityNVD Advisory· Published Oct 21, 2006· Updated Apr 23, 2026
CVE-2006-5442
CVE-2006-5442
Description
ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded JavaScript code via a view.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/22395nvdVendor Advisory
- securityreason.com/securityalert/1755nvd
- viewvc.tigris.org/servlets/ReadMsgnvd
- viewvc.tigris.org/source/browse/viewvc/trunk/CHANGESnvd
- www.hardened-php.net/advisory_102006.134.htmlnvd
- www.securityfocus.com/archive/1/448762/100/0/threadednvd
- www.securityfocus.com/bid/20543nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29576nvd
News mentions
0No linked articles in our index yet.