Release date:
Updated on:
Affected Systems:
Microsoft SharePoint Server 2010
Microsoft SharePoint Foundation 2010 SP1
Microsoft SharePoint Foundation 2010
Microsoft infopath2010
Microsoft InfoPath 2007 SP2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54313
Cve id: CVE-2012-1858
SharePoint Server is a Server function integration suite that provides comprehensive Content Management and Enterprise Search, accelerating shared business processes and simplifying cross-border information sharing.
SharePoint Server has the information leakage vulnerability in HTML string filtering. After successful exploitation, it can execute cross-site scripting attacks and run scripts with the current user permissions.
<* Source: Microsoft
Link: http://secunia.com/advisories/49875/
Http://www.microsoft.com/technet/security/bulletin/MS12-050.asp
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS12-050) and patches for this:
MS12-050: Vulnerabilities in SharePoint cocould Allow Elevation of Privilege (2695502)
Link: http://www.microsoft.com/technet/security/bulletin/MS12-050.asp