MS12-007: Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)

This script is Copyright (C) 2012-2016 Tenable Network Security, Inc.

Synopsis :

A library is installed on the remote host that is affected by an
information disclosure vulnerability.

Description :

The remote Windows host is running a version of the Anti-Cross-Site
Scripting Library (AntiXSS) that is affected by an information
disclosure vulnerability.

An attacker could gain access to sensitive information if he could
pass a malicious script to a website using the sanitization function
of the Anti-Cross-Site Scripting Library.

See also :

Solution :

Microsoft has released a new version of the AntiXSS Library.

Risk factor :

Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 4.1
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 57475 ()

Bugtraq ID: 51291

CVE ID: CVE-2012-0007

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial