Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
BID:39776
Info
Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
| Bugtraq ID: | 39776 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0817 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2010 12:00AM |
| Updated: | Jun 10 2010 07:09PM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
Microsoft Windows SharePoint Services 3.0 Microsoft SharePoint Services 64-bit 3.0 SP2 Microsoft SharePoint Services 64-bit 3.0 SP1 Microsoft SharePoint Services 64-bit 3.0 Microsoft SharePoint Services 3.0 SP2 Microsoft SharePoint Services 3.0 SP1 Microsoft SharePoint Server 2007 x64 SP2 Microsoft SharePoint Server 2007 x64 SP1 Microsoft SharePoint Server 2007 x64 0 Microsoft SharePoint Server 2007 SP2 Microsoft SharePoint Server 2007 SP1 Microsoft SharePoint Server 2007 12.0.0.6421 Microsoft SharePoint Server 2007 12.0.0.6318 Microsoft SharePoint Server 2007 0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
Microsoft SharePoint Server 2007 and SharePoint Services 3.0 are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Microsoft SharePoint Server 2007 and SharePoint Services 3.0 are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
Solution / Fix
Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft SharePoint Server 2007 SP2
Microsoft SharePoint Services 3.0 SP1
Microsoft SharePoint Services 3.0 SP2
Microsoft SharePoint Services 64-bit 3.0 SP2
Microsoft SharePoint Server 2007 SP1
Microsoft SharePoint Server 2007 x64 SP1
Microsoft SharePoint Server 2007 x64 SP2
Microsoft SharePoint Services 64-bit 3.0 SP1
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft SharePoint Server 2007 SP2
-
Microsoft Security Update for Microsoft Office SharePoint Server 3.0 (KB979445), 32-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=52a55423-f33b -4cd1-919d-806972a553df
Microsoft SharePoint Services 3.0 SP1
-
Microsoft Security Update for Microsoft Windows SharePoint Services 3.0 (KB983444), 32-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=3841ceda-d0af -4e5e-8a1a-7dd954850783
Microsoft SharePoint Services 3.0 SP2
-
Microsoft Security Update for Microsoft Windows SharePoint Services 3.0 (KB983444), 32-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=3841ceda-d0af -4e5e-8a1a-7dd954850783
Microsoft SharePoint Services 64-bit 3.0 SP2
-
Microsoft Security Update for Microsoft Windows SharePoint Services 3.0 (KB983444), 64-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=94bc76d4-78e4 -4bda-8922-36c3a9d3854f
Microsoft SharePoint Server 2007 SP1
-
Microsoft Security Update for Microsoft Office SharePoint Server 3.0 (KB979445), 32-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=52a55423-f33b -4cd1-919d-806972a553df
Microsoft SharePoint Server 2007 x64 SP1
-
Microsoft Security Update for Microsoft Office SharePoint Server 2007 (KB979445), 64-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=4d84a25b-532f -4319-9ab2-90e5b82ebd90
Microsoft SharePoint Server 2007 x64 SP2
-
Microsoft Security Update for Microsoft Office SharePoint Server 2007 (KB979445), 64-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=4d84a25b-532f -4319-9ab2-90e5b82ebd90
Microsoft SharePoint Services 64-bit 3.0 SP1
-
Microsoft Security Update for Microsoft Windows SharePoint Services 3.0 (KB983444), 64-bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=94bc76d4-78e4 -4bda-8922-36c3a9d3854f
References
Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
References:
References:
- Microsoft SharePoint Homepage (Microsoft)
- Security Advisory 983438 Released (Microsoft)
- XSS in Microsoft SharePoint Server 2007 (High-Tech Bridge SA)
- XSS in Microsoft SharePoint Server 2007 ([email protected])
- ASA-2010-154 MS10-039 Vulnerabilities in Microsoft SharePoint Could Allow Elevat (Avaya)
- Microsoft Security Advisory (983438) (Microsoft)
- Microsoft Security Bulletin MS10-039 (Microsoft)