PT-2006-1123 · Microsoft · Indexing Services+1

Eiji James Yoshida

·

Publicado

2006-09-12

·

Atualizado

2019-04-30

·

CVE-2006-0032

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Windows versions 2000, XP, and Server 2003
Description: A cross-site scripting issue exists due to the Indexing Service in Microsoft Windows. When the Encoding option is set to Auto Select, remote attackers can inject arbitrary web script or HTML via a UTF-7 encoded URL. This encoded URL is then injected into an error message with a charset set to UTF-7.
Recommendations: For Microsoft Windows 2000, XP, and Server 2003, consider disabling the Indexing Service or setting the Encoding option to a value other than Auto Select to mitigate the risk of exploitation. Restrict access to the Indexing Service to minimize the risk of remote attackers injecting arbitrary web script or HTML.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0032

Produtos afetados

Indexing Services
Windows