4.3
CVSSv2

CVE-2006-0032

Published: 12/09/2006 Updated: 30/04/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote malicious users to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2003 server datacenter_edition

microsoft windows 2003 server enterprise_edition_itanium

microsoft windows 2003 server standard_64-bit

microsoft windows 2003 server web

microsoft windows xp

microsoft windows 2000

microsoft windows 2003 server datacenter_edition_itanium

microsoft windows 2003 server r2

microsoft windows 2003 server enterprise_64-bit

microsoft windows 2003 server sp1

microsoft windows 2003 server standard

microsoft windows 2000 resource_kit

microsoft windows 2003 server enterprise_edition

Exploits

source: wwwsecurityfocuscom/bid/19927/info Microsoft Indexing Service is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input before it is rendered to other users An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting us ...