Vulnerability Name: | CVE-2006-4685 (CCN-29206) | ||||||||
Assigned: | 2006-10-10 | ||||||||
Published: | 2006-10-10 | ||||||||
Updated: | 2018-10-17 | ||||||||
Summary: | The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-4685 Source: CCN Type: SA22333 Microsoft XML Core Services Information Disclosure and Code Execution Source: SECUNIA Type: UNKNOWN 22333 Source: CCN Type: SECTRACK ID: 1017033 Microsoft XML Core Services Lets Remote Users Execute Arbitrary Code or Obtain Information Source: SECTRACK Type: UNKNOWN 1017033 Source: CCN Type: ASA-2006-217 Windows Security Updates for October 2006 - (MS06-056 - MS06-065) Source: CCN Type: US-CERT VU#547212 Microsoft XML Core Services XMLHTTP ActiveX control fails to properly interpret certain HTTP operations Source: CERT-VN Type: US Government Resource VU#547212 Source: CCN Type: Microsoft Security Bulletin MS06-061 Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (924191) Source: CCN Type: Microsoft Security Bulletin MS06-071 Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (928088) Source: CCN Type: Microsoft Security Bulletin MS07-042 Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (936227) Source: OSVDB Type: UNKNOWN 29425 Source: CCN Type: OSVDB ID: 29425 Microsoft XML Core Services XMLHTTP ActiveX Control Server-side Redirect Information Disclosure Source: HP Type: UNKNOWN SSRT061264 Source: BID Type: UNKNOWN 20339 Source: CCN Type: BID-20339 Microsoft XML Core Services Information Disclosure Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-3980 Source: MS Type: UNKNOWN MS06-061 Source: XF Type: UNKNOWN msxml-xmlhttp-information-disclosure(29206) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:221 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |