Unrated severityNVD Advisory· Published Oct 24, 2006· Updated Apr 23, 2026
CVE-2006-5486
CVE-2006-5486
Description
Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.
Affected products
4- cpe:2.3:a:sun:iplanet_messaging_server:5.2:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_messaging_server:6.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sun:java_system_messaging_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:java_system_messaging_server:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:sun:java_system_messaging_server:6.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- sunsolve.sun.com/search/document.donvdPatchVendor Advisory
- secunia.com/advisories/22575nvdVendor Advisory
- securitytracker.com/idnvd
- www.securityfocus.com/bid/20708nvd
- www.vupen.com/english/advisories/2006/4183nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29806nvd
News mentions
0No linked articles in our index yet.