AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-0032

MEDIUM · CVSS 4.3 EPSS 23.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-09-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-0032
Severity
MEDIUM
CVSS
4.3
EPSS
23.24%
Microsoft Windows

Original NVD Description

Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.