CERTA-2004-AVI-120
Vulnerability from certfr_avis

Plusieurs vulnérabilités ont été découvertes dans Microsoft SharePoint Portal Server 2001.

Description

Microsoft SharePoint Portal Server 2001 permet la création de portail d'entreprise. Plusieurs sites peuvent être connectés au sein d'un même portail.

Des vulnérabilités de type "Cross Site Scripting" permettent en utilisant Microsoft SharePoint Portal Server 2001 comme rebond d'exécuter des scripts malicieux sur une machine cible.

De plus il est possible par ce même type d'attaque de voler les cookies des utilisateurs visitant ces sites.

Solution

Télécharger le Service Pack3 qui corrige ces vulnérabilités (cf. Section Documentation).

Microsoft SharePoint Portal Server 2001.

Impacted products
Vendor Product Description
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [],
  "affected_systems_content": "\u003cP\u003eMicrosoft SharePoint Portal Server 2001.\u003c/P\u003e",
  "content": "## Description\n\nMicrosoft SharePoint Portal Server 2001 permet la cr\u00e9ation de portail\nd\u0027entreprise. Plusieurs sites peuvent \u00eatre connect\u00e9s au sein d\u0027un m\u00eame\nportail.\n\nDes vuln\u00e9rabilit\u00e9s de type \"Cross Site Scripting\" permettent en\nutilisant Microsoft SharePoint Portal Server 2001 comme rebond\nd\u0027ex\u00e9cuter des scripts malicieux sur une machine cible.\n\nDe plus il est possible par ce m\u00eame type d\u0027attaque de voler les cookies\ndes utilisateurs visitant ces sites.\n\n## Solution\n\nT\u00e9l\u00e9charger le Service Pack3 qui corrige ces vuln\u00e9rabilit\u00e9s (cf. Section\nDocumentation).\n",
  "cves": [],
  "initial_release_date": "2004-04-08T00:00:00",
  "last_revision_date": "2004-04-08T00:00:00",
  "links": [
    {
      "title": "Avis de s\u00e9curit\u00e9 de Microsoft KB837017 :",
      "url": "http://www.microsoft.com/downloads/details.aspx?FamilyId=15677A92-3470-465F-9F63-E621094103E0"
    }
  ],
  "reference": "CERTA-2004-AVI-120",
  "revisions": [
    {
      "description": "version initiale.",
      "revision_date": "2004-04-08T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "Ex\u00e9cution de scripts"
    },
    {
      "description": "Vol de cookies"
    }
  ],
  "summary": "Plusieurs vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Microsoft SharePoint\nPortal Server 2001.\n",
  "title": "Vuln\u00e9rabilit\u00e9s dans Microsoft SharePoint Portal Server 2001",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Avis de s\u00e9curit\u00e9 Microsoft KB837017",
      "url": null
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…