// For flags

CVE-2009-3830

SharePoint 2007 - Team Services Source Code Disclosure

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.

La funcionalidad "descarga" en Team Services en Microsoft Office SharePoint Server 2007 v12.0.0.4518 y v12.0.0.6219 permite a atacantes remotos leer fuentes de ASP.NET a través de nombres de rutas en los parámetros SourceUrl y Source a _layouts/download.aspx.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-10-26 First Exploit
  • 2009-10-30 CVE Reserved
  • 2009-10-30 CVE Published
  • 2024-07-20 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Sharepoint Server
Search vendor "Microsoft" for product "Sharepoint Server"
2007
Search vendor "Microsoft" for product "Sharepoint Server" and version "2007"
-
Affected