CVE-2012-2520
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Microsoft InfoPath 2007 SP2 y SP3 y 2010 SP1, Communicator 2007 R2, Lync 2010 y 2010 Attendee, SharePoint Server 2007 SP2 y SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, y Office Web Apps 2010 SP1, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de una cadena modificada, también conocido como "HTML Sanitization Vulnerability."
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-05-09 CVE Reserved
- 2012-10-09 CVE Published
- 2024-08-06 CVE Updated
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/55797 | Third Party Advisory | |
http://www.securitytracker.com/id?1027625 | Third Party Advisory | |
http://www.securitytracker.com/id?1027626 | Third Party Advisory | |
http://www.securitytracker.com/id?1027627 | Third Party Advisory | |
http://www.securitytracker.com/id?1027628 | Third Party Advisory | |
http://www.securitytracker.com/id?1027629 | Third Party Advisory | |
http://www.us-cert.gov/cas/techalerts/TA12-283A.html | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14976 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-066 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Groove Server Search vendor "Microsoft" for product "Groove Server" | 2010 Search vendor "Microsoft" for product "Groove Server" and version "2010" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Infopath Search vendor "Microsoft" for product "Infopath" | 2007 Search vendor "Microsoft" for product "Infopath" and version "2007" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Infopath Search vendor "Microsoft" for product "Infopath" | 2010 Search vendor "Microsoft" for product "Infopath" and version "2010" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Lync Search vendor "Microsoft" for product "Lync" | 2010 Search vendor "Microsoft" for product "Lync" and version "2010" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Lync Search vendor "Microsoft" for product "Lync" | 2010 Search vendor "Microsoft" for product "Lync" and version "2010" | attendee |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Communicator Search vendor "Microsoft" for product "Office Communicator" | 2007 Search vendor "Microsoft" for product "Office Communicator" and version "2007" | r2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Web Apps Search vendor "Microsoft" for product "Office Web Apps" | 2010 Search vendor "Microsoft" for product "Office Web Apps" and version "2010" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Foundation Search vendor "Microsoft" for product "Sharepoint Foundation" | 2010 Search vendor "Microsoft" for product "Sharepoint Foundation" and version "2010" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Server Search vendor "Microsoft" for product "Sharepoint Server" | 2007 Search vendor "Microsoft" for product "Sharepoint Server" and version "2007" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Server Search vendor "Microsoft" for product "Sharepoint Server" | 2007 Search vendor "Microsoft" for product "Sharepoint Server" and version "2007" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Server Search vendor "Microsoft" for product "Sharepoint Server" | 2010 Search vendor "Microsoft" for product "Sharepoint Server" and version "2010" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Services Search vendor "Microsoft" for product "Sharepoint Services" | 3.0 Search vendor "Microsoft" for product "Sharepoint Services" and version "3.0" | sp2 |
Affected
|