PT-2006-1123 · Microsoft · Indexing Services+1

Eiji James Yoshida

·

Published

2006-09-12

·

Updated

2019-04-30

·

CVE-2006-0032

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Windows versions 2000, XP, and Server 2003
Description: A cross-site scripting issue exists due to the Indexing Service in Microsoft Windows. When the Encoding option is set to Auto Select, remote attackers can inject arbitrary web script or HTML via a UTF-7 encoded URL. This encoded URL is then injected into an error message with a charset set to UTF-7.
Recommendations: For Microsoft Windows 2000, XP, and Server 2003, consider disabling the Indexing Service or setting the Encoding option to a value other than Auto Select to mitigate the risk of exploitation. Restrict access to the Indexing Service to minimize the risk of remote attackers injecting arbitrary web script or HTML.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0032

Affected Products

Indexing Services
Windows