Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-4685
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-4685

Description:
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.

CVE Status:
Candidate

References:

ST
  1017033

SAID
  Secunia Advisory: SA22333

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:221

OSVDB
  29425

MS
  http://www.microsoft.com/technet/security/Bulletin/MS06-061.mspx

HP
  http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded

CERT-VN
  547212

BID
  20339


Return to the previous page.