CVE-2013-0006

CWE-1894 documents4 sources
Severity
8.8HIGH
EPSS
68.3%
top 1.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateMay 5

Description

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

🔴Vulnerability Details

2
GHSA
GHSA-4jcp-w4pp-vm92: Microsoft XML Core Services (aka MSXML) 32022-05-05
CVEList
CVE-2013-0006: Microsoft XML Core Services (aka MSXML) 32013-01-09

💥Exploits & PoCs

1
Exploit-DB
Hewlett-Packard (HP) 2620 Switch Series. Edit Admin Account - Cross-Site Request Forgery2013-09-26