Microsoft SharePoint Contact Details CVE-2011-1891 Cross Site Scripting Vulnerability
BID:49005
Info
Microsoft SharePoint Contact Details CVE-2011-1891 Cross Site Scripting Vulnerability
| Bugtraq ID: | 49005 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1891 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2011 12:00AM |
| Updated: | Sep 13 2011 12:00AM |
| Credit: | Seeker automatic application security testing solution |
| Vulnerable: |
Microsoft SharePoint Services 64-bit 3.0 SP2 Microsoft SharePoint Services 3.0 SP2 Microsoft SharePoint Foundation 2010 SP1 Microsoft SharePoint Foundation 2010 0 |
| Not Vulnerable: | |
Discussion
Microsoft SharePoint Contact Details CVE-2011-1891 Cross Site Scripting Vulnerability
Microsoft SharePoint is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions on the SharePoint site on behalf of the user, redirect the user to malicious sites, or steal the user's credentials.
Microsoft SharePoint is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions on the SharePoint site on behalf of the user, redirect the user to malicious sites, or steal the user's credentials.
Exploit / POC
Microsoft SharePoint Contact Details CVE-2011-1891 Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Microsoft SharePoint Contact Details CVE-2011-1891 Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft SharePoint Foundation 2010 SP1
Microsoft SharePoint Services 3.0 SP2
Microsoft SharePoint Foundation 2010 0
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft SharePoint Foundation 2010 SP1
-
Microsoft Security Update for Office SharePoint Foundation 2010 (KB2494001)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27 391
Microsoft SharePoint Services 3.0 SP2
-
Microsoft Security Update for Windows SharePoint Services 2007 (KB2493987), 32-bit Edition
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27 333 -
Microsoft Security Update for Windows SharePoint Services 2007 (KB2493987), 64-bit Edition
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27 345
Microsoft SharePoint Foundation 2010 0
-
Microsoft Security Update for Office SharePoint Foundation 2010 (KB2494001)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27 391
References
Microsoft SharePoint Contact Details CVE-2011-1891 Cross Site Scripting Vulnerability
References:
References:
- SharePoint Server Homepage (Microsoft)
- Microsoft Security Bulletin MS11-074 (Microsoft)
- Microsoft Security Bulletin MS11-074 - Important (Microsoft)