PT-2005-2653 · Microsoft · Sharepoint Server+2
Published
2005-05-20
·
Updated
2008-09-05
·
CVE-2005-1676
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Groove Mobile Workspace versions prior to 3.1 build 2338
Groove Mobile Workspace version 3.1a build 2364 and earlier
Groove Workspace versions prior to 2.5n build 1871
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
picture columns embedded within SharePoint lists or drop-down menus in a SharePoint list. This can lead to cross-site scripting (XSS) attacks.Recommendations
For Groove Mobile Workspace versions prior to 3.1 build 2338, update to version 3.1 build 2338 or later.
For Groove Mobile Workspace version 3.1a build 2364 and earlier, update to a version later than 3.1a build 2364.
For Groove Workspace versions prior to 2.5n build 1871, update to version 2.5n build 1871 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Groove Mobile Workspace
Groove Workspace
Sharepoint Server