Cross-Site Scripting and Spoofing Attacks in Windows SharePoint Services and SharePoint Team Services
The cross-site scripting vulnerability could allow code execution and a spoofing attack could take place because input provided to HTML redirection queries is not adequately validated.
February 8, 2005
Reported February 8, 2005 by Microsoft
VERSIONS AFFECTED
Windows SharePoint Services for Windows Server 2003
SharePoint Team Services from Microsoft
Non-Affected Software:
Windows Server 2003 for Itanium-based systems
SharePointPortal Server 2003 (all versions)
SharePoint Portal Server 2001 (all versions)
DESCRIPTION
The cross-sitescripting vulnerability could allow an intruder to execute code inthe security context of the currently logged on user.
A spoofing attackcould take place because input provided to HTML redirection queriesis not adequately validated before the input is sent to a user's Webbrowser.
VENDOR RESPONSE
Microsoft has releasedSecurity Bulletin MS05-006, "Vulnerabilityin Windows SharePoint Services and SharePoint Team Services CouldAllow Cross-Site Scripting and Spoofing Attacks (887981),"and a patch to correct the problem.
About the Author
You May Also Like