21861Third-party advisory
http://secunia.com/advisories/21861 CVE-2006-0032
Microsoft Indexing Service - Query Validation Cross-Site Scripting
Record summary
CVE-2006-0032 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Indexing Service - Query Validation Cross-Site ScriptingExploitDB exploitby Eiji James YoshidaNot analyzed1 file
References
Showing 12 of 141016826vdb entry
http://securitytracker.com/id?1016826 geocities.jp
http://www.geocities.jp/ptrs_sec/advisory09e.html VU#108884Third-party advisory
http://www.kb.cert.org/vuls/id/108884 SSRT061187Vendor advisory
http://www.securityfocus.com/archive/1/446630/100/100/threaded 20061002 IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])mailing list
http://www.securityfocus.com/archive/1/447509/100/0/threaded 20061001 Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053]mailing list
http://www.securityfocus.com/archive/1/447511/100/0/threaded 19927vdb entry
http://www.securityfocus.com/bid/19927 TA06-255AThird-party advisory
http://www.us-cert.gov/cas/techalerts/TA06-255A.html ADV-2006-3564vdb entry
http://www.vupen.com/english/advisories/2006/3564 MS06-053Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-053 ms-indexing-service-xss(28651)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/28651