This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2012-09-11
Product Visual Studio Team Foundation Server Last view 2013-12-10
Version 2010 Type
Update sp1  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:microsoft:visual_studio_team_foundation_server:2010:sp1:*:*:*:*:*:* 1
cpe:2.3:a:microsoft:visual_studio_team_foundation_server:2013:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
4.3 2013-12-10 CVE-2013-5042

Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport protocol data, aka "SignalR XSS Vulnerability."

4.3 2012-09-11 CVE-2012-1892

Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."

CWE : Common Weakness Enumeration

%idName
100% (2) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Oval Markup Language : Definitions

OvalID Name
oval:org.mitre.oval:def:15779 XSS Vulnerability - MS12-061
oval:org.mitre.oval:def:20798 SignalR XSS Vulnerability (CVE-2013-5042) - MS13-103

OpenVAS Exploits

id Description
2012-09-12 Name : MS Visual Studio Team Foundation Server Privilege Elevation Vulnerability (27...
File : nvt/secpod_ms12-061.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2013-A-0224 Microsoft ASP.NET SignalR Privilege Escalation Vulnerability
Severity: Category II - VMSKEY: V0042590
2012-B-0090 Microsoft Visual Studio Team Foundation Server Cross Site Scripting Vulnerabi...
Severity: Category II - VMSKEY: V0033787

Snort® IPS/IDS

Date Description
2014-01-10 Visual Studio Team Web Access console cross site scripting attempt
RuleID : 24137 - Type : OS-WINDOWS - Revision : 6
2014-01-10 Visual Studio Team Web Access console cross site scripting attempt
RuleID : 24136 - Type : OS-WINDOWS - Revision : 6
2014-01-10 Visual Studio Team Web Access console cross site scripting attempt
RuleID : 24135 - Type : OS-WINDOWS - Revision : 6
2014-01-10 Visual Studio Team Web Access console cross site scripting attempt
RuleID : 24134 - Type : OS-WINDOWS - Revision : 6
2014-01-10 Visual Studio Team Web Access console cross site scripting attempt
RuleID : 24133 - Type : OS-WINDOWS - Revision : 6
2014-01-10 Visual Studio Team Web Access console cross site scripting attempt
RuleID : 24132 - Type : OS-WINDOWS - Revision : 6
2014-01-10 Visual Studio Team Web Access console cross site scripting attempt
RuleID : 24131 - Type : OS-WINDOWS - Revision : 6

Nessus® Vulnerability Scanner

id Description
2013-12-11 Name: The remote host has an application that is affected by a cross-site scripting...
File: smb_nt_ms13-103.nasl - Type: ACT_GATHER_INFO
2012-09-11 Name: The remote host has an application installed that is affected by a cross-site...
File: smb_nt_ms12-061.nasl - Type: ACT_GATHER_INFO