[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Information disclosure vulnerability in Microsoft Office SharePoint Server, Services, Foundation

Deprecated
ID: oval:org.secpod.oval:def:2264Date: (C)2011-09-14   (M)2023-12-14
Class: VULNERABILITYFamily: windows




The host is installed with Microsoft Office SharePoint Server 2007 Service Pack 2 or Microsoft Office SharePoint Server 2010 or SP1 or Microsoft Windows SharePoint Services 3.0 Service Pack 2 or SharePoint Foundation 2010 or SP1 and is prone to information disclosure vulnerability. A flaw is present in the applications where SafeHTML function does not properly validate HTML. Successful exploitation allows remote attackers to perform persistent cross-site scripting attacks against users of a site that is filtering HTML content via SafeHTML.

Platform:
Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product:
Microsoft SharePoint Foundation 2010
Microsoft SharePoint Server 2010
Microsoft Windows SharePoint Services 3.0
Reference:
CVE-2011-1252
CVE    1
CVE-2011-1252
CPE    5
cpe:/a:microsoft:sharepoint_services:3.0
cpe:/a:microsoft:sharepoint_foundation:2010
cpe:/a:microsoft:groove:2010
cpe:/a:microsoft:sharepoint_server:2007
...

© SecPod Technologies