CVE Database
/

CVE-2006-4685

Back to search

CVE-2006-4685

Published: Oct 10, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.

VendorProductVersions

n/a

n/a

affected
n/a

References

22333
third-party-advisory
x_refsource_SECUNIA
VU#547212
third-party-advisory
x_refsource_CERT-VN
MS06-061
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:221
vdb-entry
signature
x_refsource_OVAL
20339
vdb-entry
x_refsource_BID
SSRT061264
vendor-advisory
x_refsource_HP
HPSBST02161
vendor-advisory
x_refsource_HP
1017033
vdb-entry
x_refsource_SECTRACK
29425
vdb-entry
x_refsource_OSVDB
ADV-2006-3980
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now