Attack (Attack ID:302039)

Release Date08/02/2012

Attack NameSharePoint Server scriptresx.ashx XSS VulnerabilityMS12-050]

Severity

BUG ID

CVE ID

 

Description

Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."

Impact:
Information gathering and system integrity compromise. Possible unauthorized administrative access to the server or application. Possible execution of arbitrary code of the attackers choosing in some cases.

Affected Systems:
Microsoft InfoPath 2007
Microsoft InfoPath 2010

Additional References:
http://technet.microsoft.com/zh-tw/security/bulletin/MS12-050

 

Solution

Ensure the system is using an up to date version of the software and has had all vendor supplied patches applied.