Microsoft SharePoint Server 2007 – Cross-Site Scripting

  • 作者: High-Tech Bridge SA
    日期: 2010-04-29
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/12450/
  • Vulnerability ID: HTB22350
    
    Reference:
    http://www.htbridge.ch/advisory/xss_in_microsoft_sharepoint_server_2007.html
    http://www.microsoft.com/technet/security/advisory/983438.mspx
    
    Product: Microsoft SharePoint Server 2007
    
    Vendor: Microsoft Corporation
    
    Vulnerable Version: 12.0.0.6421 and Probably Prior Versions Vendor
    Notification: 12 April 2010 Vulnerability Type: XSS (Сross Site Sсriрting)
    
    Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response Risk level:
    Medium
    
    Credit: High-Tech Bridge SA (http://www.htbridge.ch/)
    
    Vulnerability Details:
    
    User can execute arbitrary JavaScript code within the vulnerable
    application.
    
    The vulnerability exists due to failure in the "/_layouts/help.aspx" script
    to properly sanitize user-supplied input in "cid0" variable. Successful
    exploitation of this vulnerability could result in a compromise of the
    application, theft of cookie-based authentication credentials, disclosure or
    modification of sensitive data.
    
    An attacker can use browser to exploit this vulnerability. The following PoC
    is available:
    
    http://host/_layouts/help.aspx?cid0=MS.WSS.manifest.xml%00%3Cscript%3Ealert%28%27XSS%27%29%3C/script%3E&tid=X