The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xml_core_services | Microsoft | 3.0 (including) | 3.0 (including) |
Xml_core_services | Microsoft | 4.0 (including) | 4.0 (including) |
Xml_core_services | Microsoft | 6.0 (including) | 6.0 (including) |
Xml_parser | Microsoft | 2.6 (including) | 2.6 (including) |