PT-2009-6055 · Microsoft · Office Sharepoint Server 2007
Published
2009-10-30
·
Updated
2018-10-10
·
CVE-2009-3830
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Office SharePoint Server 2007 versions 12.0.0.4518 through 12.0.0.6219
Description
The issue allows remote attackers to read ASP.NET source code. This is achieved by manipulating pathnames in the
SourceUrl and Source parameters to the "/ layouts/download.aspx" API endpoint.Recommendations
For Microsoft Office SharePoint Server 2007 versions 12.0.0.4518 through 12.0.0.6219, consider restricting access to the
layouts/download.aspx API endpoint until a fix is available. As a temporary workaround, avoid using the SourceUrl and Source parameters in the affected API endpoint.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Sharepoint Server 2007