Microsoft SharePoint Multiple Vulnerabilities ( 13 October 2010 )
RISK: Medium Risk
1. HTML Sanitization Vulnerability
An information disclosure vulnerability exists in the way that HTML is filtered that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user.
2. HTML Sanitization Vulnerability
An information disclosure vulnerability exists in the way that the SafeHTML function sanitizes HTML. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user.
Impact
- Information Disclosure
System / Technologies affected
- Microsoft Windows SharePoint Services 3.0
- Microsoft SharePoint Foundation 2010
- Microsoft Office SharePoint Server 2007
- Microsoft Groove Server 2010
- Microsoft Office Web Apps
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
- Microsoft Windows SharePoint Services 3.0 Service Pack 2 (32-bit versions)
- Microsoft Windows SharePoint Services 3.0 Service Pack 2 (64-bit versions)
- Microsoft SharePoint Foundation 2010
- Microsoft Office SharePoint Server 2007 Service Pack 2 (32-bit editions)
- Microsoft Office SharePoint Server 2007 Service Pack 2 (64-bit editions)
- Microsoft Groove Server 2010
- Microsoft Office Web Apps
Vulnerability Identifier
Source
Related Link
Share with