Show plain JSON{"id": "CVE-2006-0032", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2006-09-12T23:07:00.000", "references": [{"url": "http://secunia.com/advisories/21861", "tags": ["Patch", "Vendor Advisory"], "source": "secure@microsoft.com"}, {"url": "http://securitytracker.com/id?1016826", "source": "secure@microsoft.com"}, {"url": "http://www.geocities.jp/ptrs_sec/advisory09e.html", "source": "secure@microsoft.com"}, {"url": "http://www.kb.cert.org/vuls/id/108884", "tags": ["US Government Resource"], "source": "secure@microsoft.com"}, {"url": "http://www.securityfocus.com/archive/1/446630/100/100/threaded", "source": "secure@microsoft.com"}, {"url": "http://www.securityfocus.com/archive/1/446630/100/100/threaded", "source": "secure@microsoft.com"}, {"url": "http://www.securityfocus.com/archive/1/447509/100/0/threaded", "source": "secure@microsoft.com"}, {"url": "http://www.securityfocus.com/archive/1/447511/100/0/threaded", "source": "secure@microsoft.com"}, {"url": "http://www.securityfocus.com/bid/19927", "tags": ["Patch"], "source": "secure@microsoft.com"}, {"url": "http://www.us-cert.gov/cas/techalerts/TA06-255A.html", "tags": ["US Government Resource"], "source": "secure@microsoft.com"}, {"url": "http://www.vupen.com/english/advisories/2006/3564", "source": "secure@microsoft.com"}, {"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-053", "source": "secure@microsoft.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28651", "source": "secure@microsoft.com"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A535", "source": "secure@microsoft.com"}, {"url": "http://secunia.com/advisories/21861", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securitytracker.com/id?1016826", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.geocities.jp/ptrs_sec/advisory09e.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.kb.cert.org/vuls/id/108884", "tags": ["US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/446630/100/100/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/446630/100/100/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/447509/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/447511/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/19927", "tags": ["Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.us-cert.gov/cas/techalerts/TA06-255A.html", "tags": ["US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2006/3564", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-053", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28651", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A535", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7."}, {"lang": "es", "value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el Indexing Service dentro de Microsoft Windows 2000, XP, y Server 2003, cuando la opci\u00f3n Encoding est\u00e1 asiganado a Auto Select, permite a un atacante remoto inyectar secuencias de comandos web o HTML a trav\u00e9s de una URL codificada UTF-7, el cual es inyectado dentro de un mensaje de error cuyo conjunto de caracteres est\u00e1 asignado a UTF-7."}], "lastModified": "2025-04-03T01:03:51.193", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD"}, {"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "294EBA01-147B-4DA0-937E-ACBB655EDE53"}, {"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E8B7346-F2AA-434C-A048-7463EC1BB117"}, {"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE1A6107-DE00-4A1C-87FC-9E4015165B5B"}, {"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}, {"criteria": "cpe:2.3:o:microsoft:windows_2000:resource_kit:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B78BF2C4-417B-4EF8-B77C-90305C1D2AD2"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "480D8321-EB2F-4626-A16B-F3C2B771EDB3"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3538DA2-B040-426D-9ADC-7C5BE9C2D4E4"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:sp1_beta_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54836D69-7BBE-4B91-9548-ECDF8AA02901"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_itanium:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FAFE013-D614-4C4B-BD62-2C58302C5115"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2E659E8-642B-4B83-9B08-0D936576B440"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1_beta_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19002473-CCAC-4F14-9176-7F08C637AB77"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B127407D-AE50-4AFE-A780-D85B5AF44A2D"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6E3EB90-92C9-4B69-B58C-087D382DC579"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition:sp1_beta_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24FD136F-8064-44C4-A9B0-1E793EB6FB6D"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_itanium:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A76783D-078D-4D68-B6DA-EE2096639881"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9ED6C754-BE0E-41CA-B674-90C43494A8AD"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1_beta_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80EB9AF9-B2D1-4B90-8BB4-E63484289CD5"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34ACB544-87DD-4D9A-99F0-A10F48C1EE05"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:enterprise:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E9E190B-A109-4177-A5B5-7BD32573762E"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:standard:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "709E6DA0-09F8-4EAB-B1B2-D4D0A7771AC1"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B5F54BB-A80E-42F2-A700-82C1240E23D0"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1_beta_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "394F16B8-C29F-445A-AA47-AA82F78CFA20"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3AC387D-BB23-4EB9-A7DA-6E3F5CD8EFD7"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B518E945-5FDE-4A37-878D-6946653C91F7"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "76BDFB16-D71F-4E33-83FD-F0F2AE2FAE7F"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:web:sp1_beta_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2A2852D-64BE-40B1-8811-02EBDC1E044E"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91D6D065-A28D-49DA-B7F4-38421FF86498"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC176BB0-1655-4BEA-A841-C4158167CC9B"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "403945FA-8676-4D98-B903-48452B46F48F"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BF263CB-4239-4DB0-867C-9069ED02CAD7"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49693FA0-BF34-438B-AFF2-75ACC8A6D2E6"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A05337E-18A5-4939-85A0-69583D9B5AD9"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E43BBC5A-057F-4BE2-B4BB-6791DDB0B9C1"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E439FA5-78BF-41B1-BAEC-C1C94CE86F2E"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB2BE2DE-7B06-47ED-A674-15D45448F357"}], "operator": "OR"}]}], "sourceIdentifier": "secure@microsoft.com", "evaluatorSolution": "Successful exploitation requires that the Indexing service is accessible through IIS."}