Vulnerabilities > Microsoft > Sharepoint Server > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2011-09-12 | CVE-2009-5092 | Cross-Site Scripting vulnerability in Microsoft Fast ESP 5.0.9 Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |
2010-09-17 | CVE-2010-3324 | Cross-Site Scripting vulnerability in Microsoft products The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257. | 4.3 |
2010-04-29 | CVE-2010-0817 | Cross-Site Scripting vulnerability in Microsoft Sharepoint Server and Sharepoint Services Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter. | 4.3 |
2009-10-30 | CVE-2009-3830 | Improper Input Validation vulnerability in Microsoft Sharepoint Server 2007 The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx. | 5.0 |
2008-11-12 | CVE-2008-4033 | Information Exposure vulnerability in Microsoft XML Core Services Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability." | 4.3 |
2008-04-18 | CVE-2008-1888 | Cross-Site Scripting vulnerability in Microsoft Sharepoint Server 2.0 Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor. | 4.3 |
2007-05-09 | CVE-2007-2581 | Cross-Site Scripting vulnerability in Microsoft products Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx. | 4.3 |