The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: microsoft
Published: 2012-11-14T00:00:00
Updated: 2024-08-06T20:42:55.253Z
Reserved: 2012-09-06T00:00:00
Link: CVE-2012-4776
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2012-11-14T00:55:01.747
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-4776
 Redhat
                        Redhat
                    No data.