PT-2010-2962 · Microsoft · Office Infopath+4

Chris Weber

·

Publicado

2010-06-08

·

Atualizado

2023-12-07

·

CVE-2010-1257

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office InfoPath versions 2003 SP3 through 2007 SP2 Office SharePoint Server versions 2007 SP1 through 2007 SP2 SharePoint Services versions 3.0 SP1 through 3.0 SP2 Internet Explorer version 8
Description The issue is related to a cross-site scripting (XSS) vulnerability in the toStaticHTML API. This vulnerability allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization, potentially leading to information disclosure. An attacker could exploit this vulnerability by constructing a specially crafted Web page, allowing the attacker to execute script in the user's security context against a site that is using the toStaticHTML API.
Recommendations For Microsoft Office InfoPath versions 2003 SP3 through 2007 SP2, consider disabling the toStaticHTML API until a patch is available. For Office SharePoint Server versions 2007 SP1 through 2007 SP2, restrict access to the toStaticHTML API to minimize the risk of exploitation. For SharePoint Services versions 3.0 SP1 through 3.0 SP2, avoid using the toStaticHTML API in sensitive operations until the issue is resolved. For Internet Explorer version 8, as a temporary workaround, consider disabling the toStaticHTML() function until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1257

Produtos afetados

Internet Explorer
Office Infopath
Office Sharepoint Server
Sharepoint Services
Sharepoint Server