4.3
CVE-2006-0032
- EPSS 24.57%
- Veröffentlicht 12.09.2006 23:07:00
- Zuletzt bearbeitet 16.06.2026 22:19:45
- Erkennungen
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2000 Version resource_kit
Microsoft ≫ Windows 2003 Server Version datacenter_edition
Microsoft ≫ Windows 2003 Server Version datacenter_edition Update sp1
Microsoft ≫ Windows 2003 Server Version datacenter_edition Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version datacenter_edition_itanium
Microsoft ≫ Windows 2003 Server Version datacenter_edition_itanium Update sp1
Microsoft ≫ Windows 2003 Server Version datacenter_edition_itanium Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version enterprise_64-bit
Microsoft ≫ Windows 2003 Server Version enterprise_edition Update sp1
Microsoft ≫ Windows 2003 Server Version enterprise_edition Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version enterprise_edition_itanium
Microsoft ≫ Windows 2003 Server Version enterprise_edition_itanium Update sp1
Microsoft ≫ Windows 2003 Server Version enterprise_edition_itanium Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version r2 Edition datacenter_64-bit
Microsoft ≫ Windows 2003 Server Version sp1 Edition enterprise
Microsoft ≫ Windows 2003 Server Version standard
Microsoft ≫ Windows 2003 Server Version standard Update sp1
Microsoft ≫ Windows 2003 Server Version standard Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version standard_64-bit
Microsoft ≫ Windows 2003 Server Version web
Microsoft ≫ Windows 2003 Server Version web Update sp1
Microsoft ≫ Windows 2003 Server Version web Update sp1_beta_1
Microsoft ≫ Windows Xp Edition 64-bit
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Edition media_center
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition home
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition home
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 24.57% | 0.977 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://www.securityfocus.com/archive/1/446630/100/100/threaded
http://www.us-cert.gov/cas/techalerts/TA06-255A.html
http://secunia.com/advisories/21861
http://securitytracker.com/id?1016826
http://www.geocities.jp/ptrs_sec/advisory09e.html
http://www.kb.cert.org/vuls/id/108884
http://www.securityfocus.com/archive/1/447509/100/0/threaded
http://www.securityfocus.com/archive/1/447511/100/0/threaded
http://www.securityfocus.com/bid/19927
http://www.vupen.com/english/advisories/2006/3564
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-053
https://exchange.xforce.ibmcloud.com/vulnerabilities/28651
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A535