Microsoft XML Core Services VulnerabilityID: oval:org.mitre.oval:def:221 | Date: (C)2006-10-11 (M)2021-09-28 |
Class: VULNERABILITY | Family: windows |
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
Platform: |
Microsoft Windows 2000 |
Microsoft Windows 7 |
Microsoft Windows 8 |
Microsoft Windows Server 2003 |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows Vista |
Microsoft Windows XP |
Microsoft Windows 8.1 |
Microsoft Windows Server 2012 R2 |
Product: |
Microsoft XML Core Services 3.0 |
Microsoft XML Core Services 4.0 |
Microsoft XML Core Services 5.0 |
Microsoft XML Core Services 6.0 |