← Back

CVE-2006-0032

nvd nist
Published: Sep 12, 2006Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.

Affected (36)

3 products
Windows 2000
Windows 2003 Server
Windows Xp
Configuration A
36 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
All versions
All versions
All versions
Version resource_kit
Microsoft
Version datacenter_edition
Version datacenter_edition sp1
Version datacenter_edition sp1_beta_1
Version datacenter_edition_itanium
Version datacenter_edition_itanium sp1
Version datacenter_edition_itanium sp1_beta_1
Version enterprise_64-bit
Version enterprise_edition sp1
Version enterprise_edition sp1_beta_1
Version enterprise_edition_itanium
Version enterprise_edition_itanium sp1
Version enterprise_edition_itanium sp1_beta_1
Version r2
Version sp1
Version standard
Version standard sp1
Version standard sp1_beta_1
Version standard_64-bit
Version web
Version web sp1
Version web sp1_beta_1
Microsoft
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions

References (26)

Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Patch
Source: secure@microsoft.com
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.