| Microsoft Windows Knowledge Base Article 2663841 update is not installed (WinMs12kb2663841Update) |
|---|
| Vuln ID: | 72887 | |
|---|---|---|
| Risk Level: | High |
WinMs12kb2663841Update |
| Platforms: | Microsoft SharePoint Foundation: 2010, Microsoft Sharepoint Server: 2010, Microsoft SharePoint Foundation: 2010 SP1, Microsoft Sharepoint Server: 2010 SP1 | |
| Description: | Microsoft Windows Knowledge Base Article 2663841 update is not installed on the system, which could allow an attacker to exploit the following vulnerabilities: Microsoft SharePoint is vulnerable to cross-site scripting, caused by the improper validation of input by the inplview.aspx script. By persuading a victim to visit a specially-crafted Web site, a remote attacker could inject malicious content in the browser of the victim to obtain sensitive information and gain elevated privileges on the system. Microsoft SharePoint is vulnerable to cross-site scripting, caused by the improper validation of input by the themeweb.aspx script. By persuading a victim to visit a specially-crafted Web site, a remote attacker could inject malicious content in the browser of the victim to obtain sensitive information and gain elevated privileges on the system. Microsoft SharePoint is vulnerable to cross-site scripting, caused by the improper validation of input by the wizardlist.aspx script. By persuading a victim to visit a specially-crafted Web site, a remote attacker could inject malicious content in the browser of the victim to obtain sensitive information and gain elevated privileges on the system. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS12-011. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS12-011 IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2012-0017 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |