Windows 7 Forums


Windows 7: MS SharePoint bug exposes credentials, sensitive data.

30 Apr 2010   #1
JMH

Win 7 Ultimate 64-bit. SP1.
 
 
MS SharePoint bug exposes credentials, sensitive data.

Quote:
Microsoft says it's investigating a security flaw in older versions of its SharePoint Server product that an independent researcher says can easily expose sensitive data and user authentication credentials.

The XSS, or cross-site scripting, vulnerability has been confirmed in SharePoint Server 2007 and is likely also present in earlier versions of the content management system software, an advisory from High-Tech Bridge warned. It allows adversaries to inject malicious javascript into the application by appending commands to the address of the targeted system.

"The vulnerability exists due to failure in the '/_layouts/help.aspx' script to properly sanitize user-supplied input in 'cid0' variable," the advisory states. "Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data."
Source -
Microsoft SharePoint bug exposes credentials, sensitive data ? The Register

My System SpecsSystem Spec

Reply

 MS SharePoint bug exposes credentials, sensitive data. problems?



Thread Tools



Similar help and support threads for: MS SharePoint bug exposes credentials, sensitive data.
Thread Forum
Doctor Web exposes 550,000 strong Mac botnet Security News
Flash drives dangerously hard to purge of sensitive data News
Old QuickTime flaw exposes IE System Security
Protecting Sensitive Data with AD RMS. Chillout Room
Kaspersky breach exposes sensitive database, hacker claims System Security


All times are GMT -5. The time now is 02:01 AM.


Seven Forums Android App Seven Forums IOS App Follow us on Facebook

Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32