First published: Thu Apr 29 2010(Updated: )
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Server 2010 | =2007 | |
Microsoft SharePoint Services | =3.0-sp1 | |
Microsoft SharePoint Services | =3.0-sp1 | |
Microsoft SharePoint Services | =3.0-sp2 | |
Microsoft SharePoint Services | =3.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0817 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2010-0817, you should apply the latest security updates and patches from Microsoft for SharePoint Server 2007 and SharePoint Services 3.0.
CVE-2010-0817 affects users of Microsoft SharePoint Server 2007 and SharePoint Services versions 3.0 SP1 and SP2.
CVE-2010-0817 exploits a cross-site scripting vulnerability that allows remote attackers to inject arbitrary web scripts via the cid0 parameter.
Yes, CVE-2010-0817 remains a concern for installations still running the affected versions of SharePoint without the recommended updates.