Subscribe to Windows IT Pro
February 09, 2005 12:00 AM

Cross-Site Scripting and Spoofing Attacks in Windows SharePoint Services and SharePoint Team Services

Windows IT Pro
InstantDoc ID #45374
Rating: (0)

Reported February 8, 2005 by Microsoft

VERSIONS AFFECTED

  • Windows SharePoint Services for Windows Server 2003
  • SharePoint Team Services from Microsoft

Non-Affected Software:

  • Windows Server 2003 for Itanium-based systems
  • SharePoint Portal Server 2003 (all versions)
  • SharePoint Portal Server 2001 (all versions)

DESCRIPTION

The cross-site scripting vulnerability could allow an intruder to execute code in the security context of the currently logged on user.

A spoofing attack could take place because input provided to HTML redirection queries is not adequately validated before the input is sent to a user's Web browser.

VENDOR RESPONSE

Microsoft has released Security Bulletin MS05-006, "Vulnerability in Windows SharePoint Services and SharePoint Team Services Could Allow Cross-Site Scripting and Spoofing Attacks (887981)," and a patch to correct the problem.





Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.