This application requires Javascript for optimal performance.

MS.SharePoint.Server.Help.aspx.XSS

Release Date

May 03, 2010

Severity

medium

Impact

System Compromise: Remote attackers can gain access of victim systems.

Description

This indicates an attempt to exploit a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server.

The vulnerability is due to the application's failure to properly sanitize user-supplied data before processing it. An attacker may exploit this to execute arbitrary code.

Affected Products

Microsoft SharePoint Server 2007

Recommended Actions

Currently we are not aware of any officially supplied fix for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-0817

Reference/s

http://www.htbridge.ch/advisory/xss_in_microsoft_sharepoint_server_2007.html
http://technet.microsoft.com/en-us/security/bulletin/ms10-039.mspx (MS-ID)

Reference: VID-22848