Mario Heiderich

Researcher fromCure53
#2891of 53,633
87.5Total CVSS
Vulnerabilities · 16
Medium
14
High
2
PT-2010-4735
4.3
2010-09-17
Microsoft · Office Sharepoint Server 2007 Sp2 · CVE-2010-3324
**Name of the Vulnerable Software and Affected Versions** Microsoft Internet Explorer 8 Microsoft Windows SharePoint Services 3.0 SP2 SharePoint Foundation 2010 Office SharePoint Server 2007 SP2 Groove Server 2010 Office Web Apps (affected versions not specified) **Description** The issue allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) `@import` rule. An information disclosure vulnerability exists in the way that the `SafeHTML` function and the `toStaticHTML` API sanitize HTML, which could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user. This could enable the attacker to execute a cross-site scripting attack on the user, allowing the execution of script in the user's security context against a site that is using the `toStaticHTML` API. **Recommendations** For Microsoft Internet Explorer 8, consider disabling the `toStaticHTML` function as a temporary workaround until a patch is available. For Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, restrict access to the `SafeHTML` function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.