Summary
This host is missing an important security update according to Microsoft Bulletin MS13-035.
Impact
Successful exploitation could allow an attacker to bypass certain security restrictions and conduct cross-site scripting and spoofing attacks.
Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-035
Insight
Certain unspecified input is not properly sanitized within the HTML Sanitation component before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Affected
Microsoft SharePoint Server 2010 Service Pack 1
References
Severity
Classification
-
CVE CVE-2013-1289 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Microsoft SQL Server Elevation of Privilege Vulnerability (2984340) - Remote
- Microsoft Group Policy Preferences Privilege Elevation Vulnerability (2962486)
- Microsoft ISA Server DNS - Denial Of Service (MS03-009)
- Microsoft SharePoint Privilege Elevation Vulnerabilities (2028554)
- Microsoft Office Web Apps HTML Sanitisation Component XSS Vulnerability (2821818)