Microsoft SharePoint Server Picture Source HTML Injection Vulnerability
BID:28706
Info
Microsoft SharePoint Server Picture Source HTML Injection Vulnerability
| Bugtraq ID: | 28706 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1888 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | OneIdBeagl3 <[email protected]> |
| Vulnerable: |
Microsoft Windows SharePoint Services 2.0 |
| Not Vulnerable: | |
Discussion
Microsoft SharePoint Server Picture Source HTML Injection Vulnerability
Microsoft SharePoint Server is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data. Note that to perform attacks, an attacker requires access to a user account with sufficient privileges to edit pages.
Exploiting this issue may allow the attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Microsoft SharePoint Server 2.0 is vulnerable; other versions may also be affected.
Microsoft SharePoint Server is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data. Note that to perform attacks, an attacker requires access to a user account with sufficient privileges to edit pages.
Exploiting this issue may allow the attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Microsoft SharePoint Server 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Microsoft SharePoint Server Picture Source HTML Injection Vulnerability
Attackers can exploit this issue via a browser.
The following example exploit is available to be entered into the 'Picture Source' field:
Attackers can exploit this issue via a browser.
The following example exploit is available to be entered into the 'Picture Source' field:
Solution / Fix
Microsoft SharePoint Server Picture Source HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft SharePoint Server Picture Source HTML Injection Vulnerability
References:
References:
- Microsoft SharePoint Homepage (Microsoft)
- CAU-2008-0002: Microsoft Windows SharePoint Services Picture Source XSS ("I\)ruid"
)