Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-0032


Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.


Published

2006-09-12T23:07:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 resource_kit Yes
Operating System microsoft windows_2003_server datacenter_edition Yes
Operating System microsoft windows_2003_server datacenter_edition Yes
Operating System microsoft windows_2003_server datacenter_edition Yes
Operating System microsoft windows_2003_server datacenter_edition_itanium Yes
Operating System microsoft windows_2003_server datacenter_edition_itanium Yes
Operating System microsoft windows_2003_server datacenter_edition_itanium Yes
Operating System microsoft windows_2003_server enterprise_64-bit Yes
Operating System microsoft windows_2003_server enterprise_edition Yes
Operating System microsoft windows_2003_server enterprise_edition Yes
Operating System microsoft windows_2003_server enterprise_edition_itanium Yes
Operating System microsoft windows_2003_server enterprise_edition_itanium Yes
Operating System microsoft windows_2003_server enterprise_edition_itanium Yes
Operating System microsoft windows_2003_server r2 Yes
Operating System microsoft windows_2003_server sp1 Yes
Operating System microsoft windows_2003_server standard Yes
Operating System microsoft windows_2003_server standard Yes
Operating System microsoft windows_2003_server standard Yes
Operating System microsoft windows_2003_server standard_64-bit Yes
Operating System microsoft windows_2003_server web Yes
Operating System microsoft windows_2003_server web Yes
Operating System microsoft windows_2003_server web Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes

References