CVE-2006-4685
published 2006-10-10CVE-2006-4685: The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows…
PriorityP421low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
19.70%
97.1th percentile
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
| microsoft | xml_parser | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vulncheck2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9w44-mcv5-p9qh: The XMLHTTP ActiveX control in Microsoft XML Parser 2
ghsa_unreviewed·2022-05-01
CVE-2006-4685 [LOW] GHSA-9w44-mcv5-p9qh: The XMLHTTP ActiveX control in Microsoft XML Parser 2
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
GHSA
GHSA-x5x2-7mmp-555x: Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4
ghsa_unreviewed·2022-05-01·CVSS 2.6
CVE-2006-5745 [LOW] GHSA-x5x2-7mmp-555x: Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
VulnCheck
Microsoft XML Core Services Vulnerability
vulncheck·2006·CVSS 2.6
CVE-2006-5745 [LOW] Microsoft XML Core Services Vulnerability
Microsoft XML Core Services Vulnerability
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
Affected: Microsoft XMP Core Services
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071; https://www.virusbulletin.com/virusbulletin/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22333http://securitytracker.com/id?1017033http://www.kb.cert.org/vuls/id/547212http://www.osvdb.org/29425http://www.securityfocus.com/archive/1/449179/100/0/threadedhttp://www.securityfocus.com/bid/20339http://www.vupen.com/english/advisories/2006/3980https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-061https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A221http://secunia.com/advisories/22333http://securitytracker.com/id?1017033http://www.kb.cert.org/vuls/id/547212http://www.osvdb.org/29425http://www.securityfocus.com/archive/1/449179/100/0/threadedhttp://www.securityfocus.com/bid/20339http://www.vupen.com/english/advisories/2006/3980https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-061https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A221
2006-10-10
Published