CVE-2011-0653: XSS
Published Sep 15, 2011
·Updated
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
Affected Software
3 affected components
Microsoft SharePoint Server=2010-sp1
Microsoft SharePoint Foundation=2010
Microsoft SharePoint Server=2010
Event History
Sep 15, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0653?
CVE-2011-0653 has a medium severity rating due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2011-0653?
To fix CVE-2011-0653, apply the security update provided by Microsoft for SharePoint Server 2010 and SharePoint Foundation 2010.
3
What products are affected by CVE-2011-0653?
CVE-2011-0653 affects Microsoft SharePoint Server 2010 Gold, SP1, and SharePoint Foundation 2010.
4
Can CVE-2011-0653 be exploited remotely?
Yes, CVE-2011-0653 can be exploited remotely by injecting arbitrary web scripts via the URI.
5
What type of vulnerability is CVE-2011-0653?
CVE-2011-0653 is identified as a Cross-Site Scripting (XSS) vulnerability.