MS13-035: Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (2821818)

Medium Nessus Plugin ID 65882


The remote host is affected by a cross-site scripting vulnerability.


The version of InfoPath, SharePoint Server, SharePoint Foundation, Groove Server, or Office Web Apps running on the remote host is affected by an unspecified cross-site scripting vulnerability. An attacker could exploit this by tricking a user into requesting specially crafted SharePoint content, resulting in arbitrary script code execution.


Microsoft has released a set of patches for InfoPath 2010, SharePoint Server 2010, SharePoint Foundation 2010, Groove Server 2010, and Office Web Apps 2010.

See Also

Plugin Details

Severity: Medium

ID: 65882

File Name: smb_nt_ms13-035.nasl

Version: $Revision: 1.11 $

Type: local

Agent: windows

Published: 2013/04/10

Modified: 2017/07/26

Dependencies: 57033, 49977, 27524, 13855

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/a:microsoft:groove_server, cpe:/a:microsoft:infopath, cpe:/a:microsoft:office_web_apps, cpe:/a:microsoft:sharepoint_foundation, cpe:/a:microsoft:sharepoint_server

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2013/04/09

Vulnerability Publication Date: 2013/04/09

Reference Information

CVE: CVE-2013-1289

BID: 58883

OSVDB: 92129

MSFT: MS13-035

MSKB: 2687421, 2687422, 2687424, 2760406, 2760408, 2760777, 2810059

IAVA: 2013-A-0083