CVE-2008-5026
LOW severity · CVSS 3.5 · Cross-site scripting (XSS)
3.5CVSS LOW
Summary
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)9%
AV:N/AC:M/Au:S/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://archives.neohapsis.com/archives/bugtraq/2008-11/0055.html
- http://archives.neohapsis.com/archives/bugtraq/2008-11/0056.html
- http://archives.neohapsis.com/archives/bugtraq/2008-11/0058.html
- http://www.pomcor.com/whitepapers/file_sharing_security.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46590