CVE-2006-4685

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 October 2006

Summary

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.

References

EPSS Score

2% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.