[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Team Foundation Server Cross-site Scripting Vulnerability

ID: oval:org.secpod.oval:def:49168Date: (C)2018-11-16   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The host is installed with Team Foundation 2018 Server Update 1.1 or Update 3 and is prone to a cross-site scripting vulnerability. The application fails to properly sanitize user provided input. On successful exploitation, an attacker could send a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised page.

Platform:
Microsoft Windows 10
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Product:
Microsoft Visual Studio Team Foundation Server 2018 Update 1.1
Microsoft Visual Studio Team Foundation Server 2018 Update 3
Microsoft Visual Studio Team Foundation Server 2018 Update 3.1
Microsoft Visual Studio Team Foundation Server 2017 Update 3.1
Reference:
CVE-2018-8602
CVE    1
CVE-2018-8602
CPE    6
cpe:/a:microsoft:visual_studio_team_foundation_server:2017:u3.1
cpe:/a:microsoft:visual_studio_team_foundation_server:2017
cpe:/a:microsoft:visual_studio_team_foundation_server:2018
cpe:/a:microsoft:visual_studio_team_foundation_server:2018:u1.1
...

© SecPod Technologies