Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
BID:12476
Info
Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
| Bugtraq ID: | 12476 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0049 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | The discoverer of this vulnerability is currently unknown. Microsoft reported this issue. |
| Vulnerable: |
Microsoft Windows SharePoint Services Windows Server 2003 SP1 Microsoft Windows SharePoint Services Windows Server 2003 Microsoft SharePoint Team Services from Microsoft |
| Not Vulnerable: | |
Discussion
Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
A cross-site scripting and spoofing vulnerability affects Microsoft Windows SharePoint Services and SharePoint Team Services.
A remote attacker may carry out a cross-site scripting attack to execute arbitrary HTML and script code in a user's browser. It is also possible to poison Web browser and intermediate proxy server caches by placing spoofed content in the caches.
A cross-site scripting and spoofing vulnerability affects Microsoft Windows SharePoint Services and SharePoint Team Services.
A remote attacker may carry out a cross-site scripting attack to execute arbitrary HTML and script code in a user's browser. It is also possible to poison Web browser and intermediate proxy server caches by placing spoofed content in the caches.
Exploit / POC
Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
An exploit is not required to leverage this issue.
An exploit is not required to leverage this issue.
Solution / Fix
Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
Solution:
Microsoft has released updates to address this vulnerability on supported platforms.
Microsoft SharePoint Team Services from Microsoft
Microsoft Windows SharePoint Services Windows Server 2003 SP1
Solution:
Microsoft has released updates to address this vulnerability on supported platforms.
Microsoft SharePoint Team Services from Microsoft
-
Microsoft Security Update for SharePoint Team Services (KB890829)
http://www.microsoft.com/downloads/details.aspx?familyid=6BE3F8AD-768E -4BCB-8EB3-AD74B576038C&displaylang=en
Microsoft Windows SharePoint Services Windows Server 2003 SP1
-
Microsoft Security Update for Windows SharePoint Services (KB887981)
http://www.microsoft.com/downloads/details.aspx?familyid=6BB93661-0CE7 -46CF-B8BB-55546B58A2F2&displaylang=en
References
Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
References:
References:
- Microsoft Security Bulletin MS05-006 (Microsoft)