PT-2010-4679 · Microsoft · Office Sharepoint Server+3

CVE-2010-3243

·

Publicado

2010-10-13

·

Atualizado

2024-10-17

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer version 8 Microsoft Windows SharePoint Services versions 3.0 SP2 Microsoft Office SharePoint Server versions 2007 SP2
Description The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. This is due to an information disclosure vulnerability in the way HTML is filtered, which could enable cross-site scripting attacks. An attacker who successfully exploits this could execute a cross-site scripting attack on the user, allowing the attacker to execute script in the user's security context against a site using the toStaticHTML API.
Recommendations For Microsoft Internet Explorer version 8, update to a version that includes the fix for the HTML Sanitization Vulnerability. For Microsoft Windows SharePoint Services versions 3.0 SP2, apply the necessary security patches to address the information disclosure vulnerability. For Microsoft Office SharePoint Server versions 2007 SP2, consider disabling the toStaticHTML function as a temporary workaround until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3243

Produtos afetados

Internet Explorer
Office Sharepoint Server
Sharepoint Server
Windows Sharepoint Services