begood Posted April 29, 2010 Report Posted April 29, 2010 Vulnerability ID: HTB22350Reference:http://www.htbridge.ch/advisory/xss_in_microsoft_sharepoint_server_2007.htmlProduct: Microsoft SharePoint Server 2007Vendor: Microsoft CorporationVulnerable Version: 12.0.0.6421 and Probably Prior Versions VendorNotification: 12 April 2010 Vulnerability Type: XSS (?ross Site S?ri?ting)Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response Risk level:MediumCredit: High-Tech Bridge SA (http://www.htbridge.ch/)Vulnerability Details:User can execute arbitrary JavaScript code within the vulnerableapplication.The vulnerability exists due to failure in the "/_layouts/help.aspx" scriptto properly sanitize user-supplied input in "cid0" variable. Successfulexploitation of this vulnerability could result in a compromise of theapplication, theft of cookie-based authentication credentials, disclosure ormodification of sensitive data.An attacker can use browser to exploit this vulnerability. The following PoCis available:http://host/_layouts/help.aspx?cid0=MS.WSS.manifest.xml%00%3Cscript%3Ealert%28%27XSS%27%29%3C/script%3E&tid=X Quote