[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Server input validation information disclosure vulnerability in Microsoft Lync and skype for business - CVE-2015-6061

ID: oval:org.secpod.oval:def:31014Date: (C)2015-11-13   (M)2024-05-03
Class: VULNERABILITYFamily: windows




The host is installed with Microsoft Lync 2010, Microsoft Skype For business 2016, Microsoft Skype For Business Basic 2016, Microsoft Lync Basic 2013 or Microsoft Lync 2010 Attendee and is prone to a server input validation information disclosure vulnerability. A flaw is present in the application, which improperly sanitizes specially crafted content. Successful exploitation could allow attackers to execute HTML and JavaScript content.

Platform:
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows Server 2012
Microsoft Windows Server 2016
Microsoft Windows Server 2012 R2
Product:
Microsoft Lync 2010
Microsoft Lync Basic 2013
Microsoft Lync 2010 Attendee
Microsoft Skype For Business 2016
Microsoft Skype For Business Basic 2016
Reference:
CVE-2015-6061
CVE    1
CVE-2015-6061
CPE    5
cpe:/a:microsoft:lync_basic_2013
cpe:/a:microsoft:lync_basic_2013:sp1
cpe:/a:microsoft:lync_attendee:2010:user_level
cpe:/a:microsoft:lync:2010
...

© SecPod Technologies