CVE-2006-5036

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/09/2006
Last modified:
09/04/2025

Description

MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:squiz:mysource_classic:*:*:*:*:*:*:*:* 2.16.2 (including)
cpe:2.3:a:squiz:mysource_matrix:*:*:*:*:*:*:*:* 3.8 (including)