PT-2011-1231 · Microsoft · Windows Server 2008 R2+3
Ruggero Strabla
·
Publicado
2011-06-16
·
Atualizado
2020-09-28
·
CVE-2011-1264
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2008 Gold
Microsoft Windows Server 2008 SP2
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2008 R2 SP1
Description
The issue is related to a cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. The exploitation of this vulnerability can enable a remote attacker to perform cross-site scripting attacks.
Recommendations
For Microsoft Windows Server 2003 SP2, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2008 Gold, apply the necessary patch or update to resolve the vulnerability.
For Microsoft Windows Server 2008 SP2, install the relevant security update to mitigate the risk.
For Microsoft Windows Server 2008 R2, apply the appropriate fix or patch to address the issue.
For Microsoft Windows Server 2008 R2 SP1, update to a newer version that includes the resolution for this vulnerability.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Active Directory Certificate Services Web Enrollment
Windows Server 2003
Windows Server 2008
Windows Server 2008 R2