A cross-site scripting vulnerability exists in a server running a vulnerable version of the .Net Framework 2.0 that could inject a client side script in the user's browser. The script could spoof content, disclose information, or take any action that the user could take on the affected web site.
Microsoft has released a patch to correct this issue, you can download it from the following web site: http://www.microsoft.com/technet/security/Bulletin/MS06-056.mspx
- Microsoft SharePoint Foundation Privilege Elevation Vulnerability (3000431)
- Flaw in Certificate Enrollment Control (Q323172)
- Microsoft Report Viewer Information Disclosure Vulnerability (2578230)
- Microsoft IIS Malformed File Extension Denial of Service Vulnerability
- Microsoft .NET Framework XML HMAC Truncation Vulnerability (981343)