Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-2581 | First vendor Publication | 2007-05-09 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2581 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:2286 | |||
Oval ID: | oval:org.mitre.oval:def:2286 | ||
Title: | SharePoint Privilege Elevation Vulnerability | ||
Description: | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2007-2581 | Version: | 1 |
Platform(s): | Microsoft Windows Server 2003 | Product(s): | SharePoint |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
37630 | Microsoft SharePoint PATH_INFO (query string) XSS |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2007-10-11 | IAVM : 2007-B-0031 - Windows SharePoint Services and Office SharePoint Server Remote Privilege Esc... Severity : Category II - VMSKEY : V0015306 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Office SharePoint cross site scripting attempt RuleID : 12629 - Revision : 19 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-10-09 | Name : A user can elevate his privileges through SharePoint. File : smb_nt_ms07-059.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:25 |
|
2024-11-28 12:12:18 |
|
2021-05-04 12:05:46 |
|
2021-04-22 01:06:20 |
|
2020-05-23 00:19:44 |
|
2018-10-16 21:19:57 |
|
2018-10-13 00:22:37 |
|
2017-10-11 09:23:57 |
|
2017-07-29 12:02:13 |
|
2016-08-31 12:01:28 |
|
2016-06-28 16:28:11 |
|
2016-04-26 16:07:01 |
|
2014-02-17 10:40:10 |
|
2014-01-19 21:24:07 |
|
2013-11-11 12:37:43 |
|
2013-05-11 10:25:24 |
|
2012-11-07 00:15:11 |
|