MS13-035: Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (2821818)

medium Nessus Plugin ID 65882

Synopsis

The remote host is affected by a cross-site scripting vulnerability.

Description

The version of InfoPath, SharePoint Server, SharePoint Foundation, Groove Server, or Office Web Apps running on the remote host is affected by an unspecified cross-site scripting vulnerability. An attacker could exploit this by tricking a user into requesting specially crafted SharePoint content, resulting in arbitrary script code execution.

Solution

Microsoft has released a set of patches for InfoPath 2010, SharePoint Server 2010, SharePoint Foundation 2010, Groove Server 2010, and Office Web Apps 2010.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2013/ms13-035

Plugin Details

Severity: Medium

ID: 65882

File Name: smb_nt_ms13-035.nasl

Version: 1.13

Type: local

Agent: windows

Published: 4/10/2013

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:microsoft:groove_server, cpe:/a:microsoft:infopath, cpe:/a:microsoft:office_web_apps, cpe:/a:microsoft:sharepoint_foundation, cpe:/a:microsoft:sharepoint_server

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Ease: No known exploits are available

Patch Publication Date: 4/9/2013

Vulnerability Publication Date: 4/9/2013

Reference Information

CVE: CVE-2013-1289

BID: 58883

IAVA: 2013-A-0083

MSFT: MS13-035

MSKB: 2687421, 2687422, 2687424, 2760406, 2760408, 2760777, 2810059