Short Name |
HTTP:XSS:SHAREPOINT-XSS-2
|
Severity |
Medium
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Microsoft SharePoint Cross Site Scripting injection 2
|
Release Date |
2010/06/08
|
Update Number |
1701
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: Microsoft SharePoint Cross Site Scripting injection 2
This signature detects attempts to exploit a known cross site scripting vulnerability in Microsoft SharePoint. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.
Extended Description
Microsoft SharePoint Server 2007 and SharePoint Services 3.0 are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Affected Products
- Avaya Meeting Exchange - Client Registration Server
- Avaya Meeting Exchange - Recording Server
- Avaya Meeting Exchange - Streaming Server
- Avaya Meeting Exchange - Web Conferencing Server
- Avaya Meeting Exchange - Webportal
- Avaya Messaging Application Server 4
- Avaya Messaging Application Server 5
- Avaya Messaging Application Server MM 1.1
- Avaya Messaging Application Server MM 2.0
- Avaya Messaging Application Server MM 3.0
- Avaya Messaging Application Server MM 3.1
- Avaya Messaging Application Server
- Microsoft SharePoint Server 2007 12.0.0.6318
- Microsoft SharePoint Server 2007 12.0.0.6421
- Microsoft SharePoint Server 2007 SP1
- Microsoft SharePoint Server 2007 SP2
- Microsoft SharePoint Server 2007
- Microsoft SharePoint Server 2007 x64 SP1
- Microsoft SharePoint Server 2007 x64 SP2
- Microsoft SharePoint Server 2007 x64
- Microsoft SharePoint Services 3.0 SP1
- Microsoft SharePoint Services 3.0 SP2
- Microsoft SharePoint Services 64-bit 3.0
- Microsoft SharePoint Services 64-bit 3.0 SP1
- Microsoft SharePoint Services 64-bit 3.0 SP2
- Microsoft Windows SharePoint Services 3.0
References