MS12-007: Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

A library is installed on the remote host that is affected by an
information disclosure vulnerability.

Description :

The remote Windows host is running a version of the Anti-Cross-Site
Scripting Library (AntiXSS) that is affected by an information
disclosure vulnerability.

An attacker could gain access to sensitive information if he could
pass a malicious script to a website using the sanitization function
of the Anti-Cross-Site Scripting Library.

See also :

http://www.securityfocus.com/archive/1/521307/30/0/threaded
http://technet.microsoft.com/en-us/security/bulletin/ms12-007

Solution :

Microsoft has released a new version of the AntiXSS Library.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.1
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 57475 ()

Bugtraq ID: 51291

CVE ID: CVE-2012-0007