[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege - MS12-066

ID: oval:org.secpod.oval:def:7319Date: (C)2012-10-12   (M)2022-10-10
Class: PATCHFamily: windows




The host is missing an important security update according to Microsoft security bulletin, MS12-066. The update is required to fix elevation of privilege vulnerability. A flaw is present in the applications, which fail to properly validate the HTML strings. Successful exploitation allows attackers to perform cross-site scripting attacks and run script in the security context of the logged-on user.

Platform:
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows 10
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 8.1
Microsoft Windows Server 2012 R2
Product:
Microsoft Communicator 2007 R2
Microsoft Groove Server 2010
Microsoft InfoPath 2007
Microsoft InfoPath 2010
Microsoft Lync 2010
Microsoft Office Web Apps 2010
Microsoft Lync 2010 Attendee
Microsoft SharePoint Foundation 2010
Microsoft SharePoint Server 2007
Microsoft SharePoint Server 2010
Microsoft SharePoint Services 3.0
Reference:
MS12-066
CVE-2012-2520
CVE    1
CVE-2012-2520
CPE    28
cpe:/a:microsoft:sharepoint_services:3.0:sp2
cpe:/a:microsoft:sharepoint_services:3.0:sp3
cpe:/a:microsoft:groove:2010
cpe:/a:microsoft:infopath:2010:sp1:x64
...
XCCDF    9
xccdf_com.secpod_benchmark_sample-definitions
xccdf_com.secpod_benchmark_microsoft-windows-server-2008
xccdf_scaprepo.com_benchmark_microsoft-windows-server-2008-r2
xccdf_com.secpod_benchmark_microsoft-windows-server-2003
...

© SecPod Technologies