Vulnerabilities > Microsoft > Sharepoint Services > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-05-09 CVE-2007-2581 Cross-Site Scripting vulnerability in Microsoft products
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
network
microsoft CWE-79
4.3
2004-01-20 CVE-2003-0904 Information Exposure vulnerability in Microsoft products
Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g.
network
microsoft CWE-200
6.0