Attack (Attack ID:302038)

Release Date08/02/2012

Attack NameSharePoint Server List Parameter XSS Vulnerability[MS12-050]

Severity

BUG ID

CVE ID

 

Description

Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."

Impact:
Information gathering and system integrity compromise. Possible unauthorized administrative access to the server or application. Possible execution of arbitrary code of the attackers choosing in some cases.

Affected Systems:
Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2007
Microsoft Groove Server 2010
Microsoft Windows SharePoint Services 3.0 Service Pack 2(32 bit)
Microsoft Windows SharePoint Services 3.0 Service Pack 2(64 bit)
Microsoft SharePoint Foundation 2010

Additional References:
http://www.microsoft.com/technet/security/bulletin/ms06-017.mspx

 

Solution

Ensure the system is using an up to date version of the software and has had all vendor supplied patches applied.