[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

XSS spoofing vulnerability in Microsoft Office Web Apps - CVE-2015-6037

ID: oval:org.secpod.oval:def:30010Date: (C)2015-10-15   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The host is installed with Microsoft SharePoint Server 2010, 2013, Foundation 2013, Office Web Apps 2010 or Web Apps Server 2013 and is prone to a XSS spoofing vulnerability. A flaw is present in the applications, which fail to properly sanitize a specially crafted request. Successful exploitation could allow attackers to update is required to fix multiple remote code execution vulnerabilities. The flaws are present in the applications, which fails to properly handle crafted Microsoft Office file. Successful exploitation could allow attackers to perform cross-site scripting attacks on affected systems.

Platform:
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Server 2012
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows Server 2012 R2
Product:
Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2013
Microsoft SharePoint Foundation 2013
Microsoft Office Web Apps 2010
Microsoft Office Web Apps Server 2013
Reference:
CVE-2015-6037
CVE    1
CVE-2015-6037
CPE    10
cpe:/a:microsoft:office_web_apps:2013
cpe:/a:microsoft:sharepoint_foundation:2013
cpe:/a:microsoft:office_web_apps:2010:sp2
cpe:/a:microsoft:office_web_apps:2010
...

© SecPod Technologies