Microsoft XML Core Service XMLHTTP ActiveX Control Remote Code Execution Vulnerability
|
Bugtraq ID:
|
20915
|
|
Class:
|
Boundary Condition Error
|
|
CVE:
|
CVE-2006-5745
|
|
Remote:
|
Yes
|
|
Local:
|
No
|
|
Published:
|
Nov 03 2006 12:00AM
|
|
Updated:
|
May 15 2007 08:48PM
|
|
Credit:
|
The vendor credits Robert Freeman of ISS, and Dror Shalev and Moti Jospeh of Checkpoint with the discovery of this vulnerability.
|
|
Vulnerable:
|
Microsoft XML Core Services 6.0
Microsoft XML Core Services 4.0
HP Storage Management Appliance 2.1
+
HP Storage Management Appliance III
+
HP Storage Management Appliance II
+
HP Storage Management Appliance I
Avaya S8100 Media Servers R9
Avaya S8100 Media Servers R8
Avaya S8100 Media Servers R7
Avaya S8100 Media Servers R6
Avaya S8100 Media Servers R12
Avaya S8100 Media Servers R11
Avaya S8100 Media Servers R10
Avaya S8100 Media Servers 0
+
Microsoft Windows 2000 Server
+
Microsoft Windows NT Server 4.0 SP6a
Avaya Messaging Application Server 0
|
|
|
|
Not Vulnerable:
|
|
|