PT-2005-2653 · Microsoft · Sharepoint Server+2
Publicado
2005-05-20
·
Atualizado
2008-09-05
·
CVE-2005-1676
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Groove Mobile Workspace versions prior to 3.1 build 2338
Groove Mobile Workspace version 3.1a build 2364 and earlier
Groove Workspace versions prior to 2.5n build 1871
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
picture columns embedded within SharePoint lists or drop-down menus in a SharePoint list. This can lead to cross-site scripting (XSS) attacks.Recommendations
For Groove Mobile Workspace versions prior to 3.1 build 2338, update to version 3.1 build 2338 or later.
For Groove Mobile Workspace version 3.1a build 2364 and earlier, update to a version later than 3.1a build 2364.
For Groove Workspace versions prior to 2.5n build 1871, update to version 2.5n build 1871 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Groove Mobile Workspace
Groove Workspace
Sharepoint Server