First published: Wed Aug 09 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6-windows_server_2003_sp1 | |
Internet Explorer | =5.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3643 has a moderate severity rating due to its ability to allow unauthorized remote access and execution of commands.
To fix CVE-2006-3643, upgrade to a supported version of Internet Explorer that is not vulnerable to this cross-site scripting attack.
CVE-2006-3643 affects Internet Explorer versions 5.01 and 6 on Microsoft Windows 2000 SP4 and Windows Server 2003 SP1.
CVE-2006-3643 is identified as a cross-site scripting (XSS) vulnerability.
CVE-2006-3643 can be exploited by remote authenticated users to execute arbitrary commands on the affected systems.