Back to search
CVE-2006-4685
Published: Oct 10, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
22333
third-party-advisory
x_refsource_SECUNIA
VU#547212
third-party-advisory
x_refsource_CERT-VN
MS06-061
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:221
vdb-entry
signature
x_refsource_OVAL
20339
vdb-entry
x_refsource_BID
SSRT061264
vendor-advisory
x_refsource_HP
HPSBST02161
vendor-advisory
x_refsource_HP
1017033
vdb-entry
x_refsource_SECTRACK
29425
vdb-entry
x_refsource_OSVDB
ADV-2006-3980
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now