Vulnerability Description
_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Sharepoint Server | <= 2007 |
Related Weaknesses (CWE)
References
- http://www.hacktics.com/content/advisories/AdvMS20100222.htmlExploit
- http://www.securityfocus.com/archive/1/509683/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56597
- http://www.hacktics.com/content/advisories/AdvMS20100222.htmlExploit
- http://www.securityfocus.com/archive/1/509683/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56597
FAQ
What is CVE-2010-0716?
CVE-2010-0716 is a vulnerability with a CVSS score of 3.5 (LOW). _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (a...
How severe is CVE-2010-0716?
CVE-2010-0716 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0716?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Sharepoint Server.