CVE-2006-4685
CVSS Score Not Available
55.39%
MEDIUM RiskEPSS (98th percentile)
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
Published: 10/10/2006
Modified: 4/9/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
55.39%MEDIUM Exploitation Risk
98th percentile
This vulnerability has a 55.39% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.