CVE-2006-4685

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:xml_parser:2.6:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-10-10 22:07

Updated : 2024-02-28 11:01


NVD link : CVE-2006-4685

Mitre link : CVE-2006-4685

CVE.ORG link : CVE-2006-4685


JSON object : View

Products Affected

microsoft

  • xml_parser
  • xml_core_services