PT-2005-2653 · Microsoft · Sharepoint Server+2

Published

2005-05-20

·

Updated

2008-09-05

·

CVE-2005-1676

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Groove Mobile Workspace versions prior to 3.1 build 2338 Groove Mobile Workspace version 3.1a build 2364 and earlier Groove Workspace versions prior to 2.5n build 1871
Description The issue allows remote attackers to inject arbitrary web script or HTML via the picture columns embedded within SharePoint lists or drop-down menus in a SharePoint list. This can lead to cross-site scripting (XSS) attacks.
Recommendations For Groove Mobile Workspace versions prior to 3.1 build 2338, update to version 3.1 build 2338 or later. For Groove Mobile Workspace version 3.1a build 2364 and earlier, update to a version later than 3.1a build 2364. For Groove Workspace versions prior to 2.5n build 1871, update to version 2.5n build 1871 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1676

Affected Products

Groove Mobile Workspace
Groove Workspace
Sharepoint Server