Secunia
|
|

CVE Reference: CVE-2007-2581 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2007-2581 |
|
|
Description: Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/34343 ST 1018789 SREASON http://securityreason.com/securityalert/2682 SAID Secunia Advisory: SA27148 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2286 OSVDB 37630 MS http://www.microsoft.com/technet/security/bulletin/ms07-059.mspx HP http://www.securityfocus.com/archive/1/archive/1/482366/100/0/threaded CERT http://www.us-cert.gov/cas/techalerts/TA07-282A.html BUGTRAQ http://archives.neohapsis.com/archives/bugtraq/2007-05/0196.html http://www.securityfocus.com/archive/1/archive/1/467749/100/0/threaded http://www.securityfocus.com/archive/1/archive/1/467738/100/0/threaded BID 23832 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |