← Back

CVE-2010-3324

nvd nist
Published: Sep 17, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.

Affected (6)

6 products
Groove Server
Internet Explorer
Sharepoint Foundation
Sharepoint Server
Sharepoint Services
Web Apps
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Version 2010
Version 8
Version 2010
Version 2007 sp2
Version 3.0 sp2
All versions

References (14)

Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.