PT-2010-1166 · Microsoft · Sharepoint Services 3.0+1
Publicado
2010-04-29
·
Atualizado
2018-10-12
·
CVE-2010-0817
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Server 2007 versions 12.0.0.6421 and earlier
Microsoft SharePoint Services 3.0 SP1 and SP2
Description
The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
cid0 parameter in the layouts/help.aspx page. The vulnerability is associated with the failure to protect the web page structure, which can lead to remote attackers performing cross-site scripting attacks.Recommendations
For Microsoft SharePoint Server 2007 versions 12.0.0.6421 and earlier, consider restricting access to the
layouts/help.aspx page until a fix is available.
For Microsoft SharePoint Services 3.0 SP1 and SP2, avoid using the cid0 parameter in the affected page to minimize the risk of exploitation.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sharepoint Server 2007
Sharepoint Services 3.0