Release date:
Updated on:
Affected Systems:
Microsoft SharePoint Server 2010
Microsoft SharePoint Foundation 2010 SP1
Microsoft SharePoint Foundation 2010
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54312
Cve id: CVE-2012-1859
SharePoint Server is a Server function integration suite that provides comprehensive Content Management and Enterprise Search, accelerating shared business processes and simplifying cross-border information sharing.
The cross-site scripting and privilege escalation vulnerability exists in SharePoint. Users can click a link to execute the JavaScript code controlled by attackers or publish SharePoint commands.
<* Source: Microsoft
Link: http://secunia.com/advisories/49875/
Http://www.microsoft.com/technet/security/bulletin/MS12-050.asp
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS12-050) and patches for this:
MS12-050: Vulnerabilities in SharePoint cocould Allow Elevation of Privilege (2695502)
Link: http://www.microsoft.com/technet/security/bulletin/MS12-050.asp