PT-2009-6055 · Microsoft · Office Sharepoint Server 2007

Published

2009-10-30

·

Updated

2018-10-10

·

CVE-2009-3830

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office SharePoint Server 2007 versions 12.0.0.4518 through 12.0.0.6219
Description The issue allows remote attackers to read ASP.NET source code. This is achieved by manipulating pathnames in the SourceUrl and Source parameters to the "/ layouts/download.aspx" API endpoint.
Recommendations For Microsoft Office SharePoint Server 2007 versions 12.0.0.4518 through 12.0.0.6219, consider restricting access to the layouts/download.aspx API endpoint until a fix is available. As a temporary workaround, avoid using the SourceUrl and Source parameters in the affected API endpoint.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3830

Affected Products

Office Sharepoint Server 2007