PT-2006-1123 · Microsoft · Indexing Services+1
Eiji James Yoshida
·
Published
2006-09-12
·
Updated
2019-04-30
·
CVE-2006-0032
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows versions 2000, XP, and Server 2003
Description:
A cross-site scripting issue exists due to the Indexing Service in Microsoft Windows. When the Encoding option is set to Auto Select, remote attackers can inject arbitrary web script or HTML via a UTF-7 encoded URL. This encoded URL is then injected into an error message with a charset set to UTF-7.
Recommendations:
For Microsoft Windows 2000, XP, and Server 2003, consider disabling the Indexing Service or setting the Encoding option to a value other than Auto Select to mitigate the risk of exploitation. Restrict access to the Indexing Service to minimize the risk of remote attackers injecting arbitrary web script or HTML.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Indexing Services
Windows