Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10.5 - Exploits Update (Wed Jun 23 2010)

Microsoft Sharepoint Server 2007 Cross Site Scripting Exploit

Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities  []




• Wed Jun 23 2010
The vulnerability exists due to failure in the "/_layouts/help.aspx" script to properly sanitize user-supplied input in "cid0" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Exploits Vulnerabiltiy: CVE-2010-0817



< Back to Product Updates