CVE-2007-2581
Microsoft SharePoint Server 3.0 - Cross-Site Scripting
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
Varias vulnerabilidades de tipo cross-site scripting (XSS) en Microsoft Windows SharePoint Services versiĆ³n 3.0 para Windows Server 2003 y Office SharePoint Server 2007 permiten a atacantes remotos inyectar script web o HTML arbitrario por medio del PATH_INFO (cadena de consulta) en "every main page," como fue demostrado por default.aspx.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-05-04 First Exploit
- 2007-05-09 CVE Reserved
- 2007-05-09 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2007-05/0196.html | Mailing List | |
http://osvdb.org/37630 | Vdb Entry | |
http://securityreason.com/securityalert/2682 | Third Party Advisory | |
http://securitytracker.com/id?1018789 | Vdb Entry | |
http://www.securityfocus.com/archive/1/467738/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/467749/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/23832 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA07-282A.html | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34343 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2286 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/29951 | 2007-05-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27148 | 2018-10-16 | |
http://www.securityfocus.com/archive/1/482366/100/0/threaded | 2018-10-16 | |
http://www.vupen.com/english/advisories/2007/3439 | 2018-10-16 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-059 | 2018-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Sharepoint Server Search vendor "Microsoft" for product "Sharepoint Server" | 2007 Search vendor "Microsoft" for product "Sharepoint Server" and version "2007" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Services Search vendor "Microsoft" for product "Sharepoint Services" | 3.0 Search vendor "Microsoft" for product "Sharepoint Services" and version "3.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Search vendor "Microsoft" for product "Windows 2003" | * | - |
Affected
|