First published: Mon May 02 2005(Updated: )
Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Team Services | ||
Microsoft SharePoint Portal Server | =2003 | |
Microsoft SharePoint Portal Server | =2003-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0049 has been assigned a medium severity rating because it allows for cross-site scripting (XSS) attacks.
To fix CVE-2005-0049, ensure you apply the latest updates and patches for Microsoft SharePoint Team Services and SharePoint Portal Server.
CVE-2005-0049 affects users of Microsoft SharePoint Team Services and Microsoft SharePoint Portal Server 2003.
CVE-2005-0049 can enable cross-site scripting (XSS) attacks and allow attackers to spoof the web cache.
The affected versions in CVE-2005-0049 include Microsoft SharePoint Team Services and Microsoft SharePoint Portal Server 2003 and 2003 SP1.