CVE-2006-0032
Microsoft Indexing Service - Query Validation Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el Indexing Service dentro de Microsoft Windows 2000, XP, y Server 2003, cuando la opción Encoding está asiganado a Auto Select, permite a un atacante remoto inyectar secuencias de comandos web o HTML a través de una URL codificada UTF-7, el cual es inyectado dentro de un mensaje de error cuyo conjunto de caracteres está asignado a UTF-7.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2005-11-30 CVE Reserved
- 2006-09-12 CVE Published
- 2006-09-12 First Exploit
- 2024-08-02 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1016826 | Vdb Entry | |
http://www.geocities.jp/ptrs_sec/advisory09e.html | X_refsource_misc | |
http://www.kb.cert.org/vuls/id/108884 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/447509/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/447511/100/0/threaded | Mailing List | |
http://www.us-cert.gov/cas/techalerts/TA06-255A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2006/3564 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28651 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A535 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28500 | 2006-09-12 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21861 | 2019-04-30 | |
http://www.securityfocus.com/bid/19927 | 2019-04-30 |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/archive/1/446630/100/100/threaded | 2019-04-30 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-053 | 2019-04-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | resource_kit Search vendor "Microsoft" for product "Windows 2000" and version "resource_kit" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_edition Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_edition Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_edition Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition" | sp1_beta_1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_edition_itanium Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition_itanium" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_edition_itanium Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition_itanium" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | datacenter_edition_itanium Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition_itanium" | sp1_beta_1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | enterprise_64-bit Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_64-bit" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | enterprise_edition Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_edition" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | enterprise_edition Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_edition" | sp1_beta_1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | enterprise_edition_itanium Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_edition_itanium" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | enterprise_edition_itanium Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_edition_itanium" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | enterprise_edition_itanium Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_edition_itanium" | sp1_beta_1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | r2 Search vendor "Microsoft" for product "Windows 2003 Server" and version "r2" | datacenter_64-bit |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | sp1 Search vendor "Microsoft" for product "Windows 2003 Server" and version "sp1" | enterprise |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | standard Search vendor "Microsoft" for product "Windows 2003 Server" and version "standard" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | standard Search vendor "Microsoft" for product "Windows 2003 Server" and version "standard" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | standard Search vendor "Microsoft" for product "Windows 2003 Server" and version "standard" | sp1_beta_1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | standard_64-bit Search vendor "Microsoft" for product "Windows 2003 Server" and version "standard_64-bit" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | web Search vendor "Microsoft" for product "Windows 2003 Server" and version "web" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | web Search vendor "Microsoft" for product "Windows 2003 Server" and version "web" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | web Search vendor "Microsoft" for product "Windows 2003 Server" and version "web" | sp1_beta_1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | 64-bit |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | home |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | media_center |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | gold, professional |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp1, home |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp1, media_center |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp2, home |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp2, media_center |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp2, tablet_pc |
Affected
|