← Back

CVE-2010-0817

nvd nist
Published: Apr 29, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.

Affected (5)

2 products
Sharepoint Server
Sharepoint Services
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2007
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 3.0 sp1
Version 3.0 sp1
Version 3.0 sp2
Version 3.0 sp2

Timeline

No history available yet.