Vulnerability Name: | CVE-2006-3643 (CCN-28005) | ||||||||
Assigned: | 2006-08-08 | ||||||||
Published: | 2006-08-08 | ||||||||
Updated: | 2021-07-23 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability." | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-3643 Source: CCN Type: SA21401 Microsoft Management Console Cross-Site Scripting Source: SECUNIA Type: UNKNOWN 21401 Source: CCN Type: SECTRACK ID: 1016655 Microsoft Management Console Input Validation Hole Permits Remote Code Execution Source: SECTRACK Type: UNKNOWN 1016655 Source: CCN Type: ASA-2006-154 Windows Security Updates for August 2006 - (MS06-040 - MS06-051) Source: CCN Type: US-CERT VU#927548 Microsoft Management Console cross-site scripting vulnerability Source: CERT-VN Type: Patch, US Government Resource VU#927548 Source: CCN Type: Microsoft Security Bulletin MS06-044 Vulnerability in Microsoft Management Console Could Allow Remote Code Execution (917008) Source: BID Type: UNKNOWN 19417 Source: CCN Type: BID-19417 Microsoft Management Console Zone Bypass Vulnerability Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-220A Microsoft Windows, Office, and Internet Explorer Vulnerabilities Source: CERT Type: Patch, US Government Resource TA06-220A Source: VUPEN Type: UNKNOWN ADV-2006-3213 Source: MS Type: UNKNOWN MS06-044 Source: XF Type: UNKNOWN win-mmc-resource-xss(28005) Source: XF Type: UNKNOWN win-mmc-resource-xss(28005) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:638 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |