|
|||
Release Date:08/02/2012
Attack Name:SharePoint Server scriptresx.ashx XSS VulnerabilityMS12-050]
Severity:
BUG ID:
CVE ID:
Description:
|
Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
Impact:
Information gathering and system integrity compromise. Possible unauthorized administrative access to the server or application. Possible execution of arbitrary code of the attackers choosing in some cases.
Affected Systems:
Microsoft InfoPath 2007
Microsoft InfoPath 2010
Additional References:
http://technet.microsoft.com/zh-tw/security/bulletin/MS12-050
Solution:
|
Ensure the system is using an up to date version of the software and has had all vendor supplied patches applied.