Vulnerability Name:

CVE-2006-4685 (CCN-29206)

Assigned:2006-10-10
Published:2006-10-10
Updated:2018-10-17
Summary:The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2006-4685

Source: CCN
Type: SA22333
Microsoft XML Core Services Information Disclosure and Code Execution

Source: SECUNIA
Type: UNKNOWN
22333

Source: CCN
Type: SECTRACK ID: 1017033
Microsoft XML Core Services Lets Remote Users Execute Arbitrary Code or Obtain Information

Source: SECTRACK
Type: UNKNOWN
1017033

Source: CCN
Type: ASA-2006-217
Windows Security Updates for October 2006 - (MS06-056 - MS06-065)

Source: CCN
Type: US-CERT VU#547212
Microsoft XML Core Services XMLHTTP ActiveX control fails to properly interpret certain HTTP operations

Source: CERT-VN
Type: US Government Resource
VU#547212

Source: CCN
Type: Microsoft Security Bulletin MS06-061
Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (924191)

Source: CCN
Type: Microsoft Security Bulletin MS06-071
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (928088)

Source: CCN
Type: Microsoft Security Bulletin MS07-042
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (936227)

Source: OSVDB
Type: UNKNOWN
29425

Source: CCN
Type: OSVDB ID: 29425
Microsoft XML Core Services XMLHTTP ActiveX Control Server-side Redirect Information Disclosure

Source: HP
Type: UNKNOWN
SSRT061264

Source: BID
Type: UNKNOWN
20339

Source: CCN
Type: BID-20339
Microsoft XML Core Services Information Disclosure Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2006-3980

Source: MS
Type: UNKNOWN
MS06-061

Source: XF
Type: UNKNOWN
msxml-xmlhttp-information-disclosure(29206)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:221

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_parser:2.6:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:xml_parser:2.6:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server::x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~~~itanium~:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:2003_server:sp1_itanium:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:221
    V
    Microsoft XML Core Services Vulnerability
    2008-12-08
    BACK
    microsoft xml core services 3.0
    microsoft xml core services 4.0
    microsoft xml core services 6.0
    microsoft xml parser 2.6
    microsoft xml core services 3.0
    microsoft xml core services 4.0
    microsoft office 2003 sp1
    microsoft office 2003 sp2
    microsoft xml core services 6.0
    microsoft xml parser 2.6
    microsoft windows xp - sp1
    microsoft windows 2000 - sp4
    microsoft windows 2003_server
    microsoft windows xp sp2
    microsoft windows 2003 server -
    microsoft windows 2003_server sp1
    microsoft windows 2003_server sp1_itanium