Skip to main content

CVE-2006-4685

CVSS Score Not Available
55.39%
MEDIUM RiskEPSS (98th percentile)

The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.

Published: 10/10/2006
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

55.39%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 55.39% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.