PT-2005-2653 · Microsoft · Sharepoint Server+2

Publicado

2005-05-20

·

Atualizado

2008-09-05

·

CVE-2005-1676

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Groove Mobile Workspace versions prior to 3.1 build 2338 Groove Mobile Workspace version 3.1a build 2364 and earlier Groove Workspace versions prior to 2.5n build 1871
Description The issue allows remote attackers to inject arbitrary web script or HTML via the picture columns embedded within SharePoint lists or drop-down menus in a SharePoint list. This can lead to cross-site scripting (XSS) attacks.
Recommendations For Groove Mobile Workspace versions prior to 3.1 build 2338, update to version 3.1 build 2338 or later. For Groove Mobile Workspace version 3.1a build 2364 and earlier, update to a version later than 3.1a build 2364. For Groove Workspace versions prior to 2.5n build 1871, update to version 2.5n build 1871 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1676

Produtos afetados

Groove Mobile Workspace
Groove Workspace
Sharepoint Server