>> Microsoft Management Console Library Cross Site Scripting Vulnerability (MS06-044)
Title : Microsoft Management Console Library Cross Site Scripting Vulnerability (MS06-044) VUPEN ID : VUPEN/ADV-2006-3213 CVE ID : CVE-2006-3643
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-08
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to execute arbitrary scripting code and take complete control of the affected system. This flaw is due to an input validation error in the Microsoft Management Console (MMC) where HTML embedded resource files can be directly referenced from the Internet or Intranet zone via Internet Explorer, which could be exploited by malicious people to execute arbitrary commands.