A cross-site scripting vulnerability exists in a server running a vulnerable version of the .Net Framework 2.0 that could inject a client side script in the user's browser. The script could spoof content, disclose information, or take any action that the user could take on the affected web site.
Microsoft has released a patch to correct this issue, you can download it from the following web site: http://www.microsoft.com/technet/security/Bulletin/MS06-056.mspx
- Microsoft Outlook Information Disclosure Vulnerability (2894514)
- Microsoft Windows Kernel Denial of Service Vulnerability (2556532)
- Microsoft Groove Server HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft SharePoint Foundation HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft MS00-058 security check