Cross-Site Scripting and Spoofing Attacks in Windows SharePoint Services and SharePoint Team Services

The cross-site scripting vulnerability could allow code execution and a spoofing attack could take place because input provided to HTML redirection queries is not adequately validated.

ITPro Today

February 8, 2005

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported February 8, 2005 by Microsoft

VERSIONS AFFECTED

  • Windows SharePoint Services for Windows Server 2003

  • SharePoint Team Services from Microsoft

Non-Affected Software:

  • Windows Server 2003 for Itanium-based systems

  • SharePointPortal Server 2003 (all versions)

  • SharePoint Portal Server 2001 (all versions)

DESCRIPTION

The cross-sitescripting vulnerability could allow an intruder to execute code inthe security context of the currently logged on user.

A spoofing attackcould take place because input provided to HTML redirection queriesis not adequately validated before the input is sent to a user's Webbrowser.

VENDOR RESPONSE

Microsoft has releasedSecurity Bulletin MS05-006, "Vulnerabilityin Windows SharePoint Services and SharePoint Team Services CouldAllow Cross-Site Scripting and Spoofing Attacks (887981),"and a patch to correct the problem.





Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like