Summary
Detail | |||
---|---|---|---|
Vendor | Microsoft | First view | 2010-02-26 |
Product | Sharepoint Server | Last view | 2011-09-15 |
Version | 2007 | Type | Application |
Update | sp2 | ||
Edition | x32 | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:microsoft:sharepoint_server |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
9.3 | 2011-09-15 | CVE-2011-1990 | Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Excel Services on Office SharePoint Server 2007 SP2 do not properly validate the sign of an unspecified array index, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Out of Bounds Array Indexing Vulnerability." |
9.3 | 2011-09-15 | CVE-2011-1989 | Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Excel Services on Office SharePoint Server 2007 SP2; Excel Services on Office SharePoint Server 2010 Gold and SP1; and Excel Web App 2010 Gold and SP1 do not properly parse conditional expressions associated with formatting requirements, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Conditional Expression Parsing Vulnerability." |
4 | 2011-09-15 | CVE-2011-1892 | Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability." |
7.5 | 2010-12-16 | CVE-2010-3964 | Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability." |
4.3 | 2010-10-13 | CVE-2010-3243 | Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability." |
4.3 | 2010-06-08 | CVE-2010-1257 | Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization. |
3.5 | 2010-02-26 | CVE-2010-0716 | _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (3) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
16% (1) | CWE-200 | Information Exposure |
16% (1) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
16% (1) | CWE-20 | Improper Input Validation |
SAINT Exploits
Description | Link |
---|---|
Microsoft SharePoint Office Document Load Balancer SOAP Vulnerability | More info here |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
75392 | Microsoft SharePoint XML File Arbitrary File Disclosure |
75387 | Microsoft Office Excel Unspecified Signedness Error Excel File Handling Memor... |
75386 | Microsoft Office Excel Unspecified Conditional Expression Parsing Excel File ... |
75381 | Microsoft SharePoint XML / XSL File Handling Unspecified Arbitrary File Discl... |
69817 | Microsoft SharePoint Office Document Load Balancer Crafted SOAP Request Remot... |
68548 | Microsoft IE / SharePoint Unspecified XSS |
65211 | Microsoft IE / Sharepoint toStaticHTML Information Disclosure |
50138 | Microsoft SharePoint Host Name / Port Number Persistence HTML Document Same-o... |
ExploitDB Exploits
id | Description |
---|---|
17873 | File disclosure via XEE in SharePoint 2007/2010 and DotNetNuke < 6 |
OpenVAS Exploits
id | Description |
---|---|
2011-09-22 | Name : Microsoft SharePoint SafeHTML Information Disclosure Vulnerabilities (2412048) File : nvt/secpod_ms10-072.nasl |
2011-09-14 | Name : Microsoft Office Excel Remote Code Execution Vulnerabilities (2587505) File : nvt/secpod_ms11-072.nasl |
2011-09-14 | Name : Microsoft SharePoint Multiple Privilege Escalation Vulnerabilities (2451858) File : nvt/secpod_ms11-074.nasl |
2010-12-29 | Name : Microsoft SharePoint Could Allow Remote Code Execution Vulnerability (2455005) File : nvt/secpod_ms10-104.nasl |
2010-10-13 | Name : Microsoft Internet Explorer Multiple Vulnerabilities (2360131) File : nvt/secpod_ms10-071.nasl |
2010-06-09 | Name : Microsoft Internet Explorer Multiple Vulnerabilities (982381) File : nvt/secpod_ms10-035.nasl |
2010-06-09 | Name : Microsoft SharePoint Privilege Elevation Vulnerabilities (2028554) File : nvt/secpod_ms10-039.nasl |
2010-03-05 | Name : Microsoft SharePoint Cross Site Scripting Vulnerability File : nvt/gb_ms_sharepoint_xss_vuln.nasl |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2011-B-0115 | Multiple Vulnerabilities in Microsoft Office SharePoint Severity: Category II - VMSKEY: V0030239 |
2011-A-0124 | Multiple Vulnerabilities in Microsoft Office Excel Severity: Category II - VMSKEY: V0030245 |
2010-A-0079 | Multiple Vulnerabilities in Microsoft Office SharePoint Severity: Category II - VMSKEY: V0024377 |
Snort® IPS/IDS
Date | Description |
---|---|
2019-04-23 | Microsoft Office Excel conditional code execution attempt RuleID : 49501 - Type : FILE-OFFICE - Revision : 1 |
2019-04-23 | Microsoft Office Excel conditional code execution attempt RuleID : 49500 - Type : FILE-OFFICE - Revision : 1 |
2014-12-09 | Microsoft Office invalid MS-OGRAPH DataFormat buffer overflow attempt RuleID : 32377 - Type : FILE-OFFICE - Revision : 4 |
2014-01-10 | Microsoft Office Excel conditional code execution attempt RuleID : 25331 - Type : FILE-OFFICE - Revision : 9 |
2014-01-10 | Microsoft Office Excel conditional code execution attempt RuleID : 25330 - Type : FILE-OFFICE - Revision : 9 |
2014-01-10 | Microsoft Office invalid MS-OGRAPH DataFormat buffer overflow attempt RuleID : 20128 - Type : FILE-OFFICE - Revision : 20 |
2014-01-10 | Microsoft Office Excel Conditional Formatting record vulnerability RuleID : 20127 - Type : FILE-OFFICE - Revision : 14 |
2014-01-10 | Microsoft Office SharePoint XML external entity exploit attempt RuleID : 20115 - Type : SERVER-WEBAPP - Revision : 10 |
2014-01-10 | Microsoft Internet Explorer and SharePoint toStaticHTML information disclosur... RuleID : 19322 - Type : BROWSER-IE - Revision : 10 |
2014-01-10 | Microsoft Office SharePoint document conversion remote code excution attempt RuleID : 18238 - Type : SERVER-WEBAPP - Revision : 13 |
2014-01-10 | Microsoft Internet Explorer 8 XSS in toStaticHTML API attempt RuleID : 17766 - Type : BROWSER-IE - Revision : 15 |
2014-01-10 | Microsoft Internet Explorer 8 cross-site scripting attempt RuleID : 16658 - Type : BROWSER-IE - Revision : 7 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2011-09-14 | Name: An application installed on the remote Mac OS X host is affected by multiple ... File: macosx_ms11-072.nasl - Type: ACT_GATHER_INFO |
2011-09-14 | Name: Arbitrary code can be executed on the remote host through Microsoft Office. File: smb_nt_ms11-072.nasl - Type: ACT_GATHER_INFO |
2011-09-14 | Name: The remote host is affected by multiple privilege escalation and information ... File: smb_nt_ms11-074.nasl - Type: ACT_GATHER_INFO |
2010-12-15 | Name: The remote host has a remote code execution vulnerability. File: smb_nt_ms10-104.nasl - Type: ACT_GATHER_INFO |
2010-10-18 | Name: The remote host is affected by multiple cross-site scripting vulnerabilities. File: safehtml_ms10_072.nasl - Type: ACT_GATHER_INFO |
2010-10-13 | Name: Arbitrary code can be executed on the remote host through a web browser. File: smb_nt_ms10-071.nasl - Type: ACT_GATHER_INFO |
2010-10-13 | Name: The remote host is affected by multiple cross-site scripting vulnerabilities. File: smb_nt_ms10-072.nasl - Type: ACT_GATHER_INFO |
2010-06-09 | Name: Arbitrary code can be executed on the remote host through a web browser. File: smb_nt_ms10-035.nasl - Type: ACT_GATHER_INFO |
2010-06-09 | Name: The remote host has multiple vulnerabilities. File: smb_nt_ms10-039.nasl - Type: ACT_GATHER_INFO |