Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
XSS in Microsoft SharePoint May 04 2007 10:01PM
ville solarius gmail com
Hi!
I think this is a XSS in MS SharePoint, you can reproduce it in SharePoint test server using for example following url:

http://www.example.com/sharepoint/default.aspx/%22);}if(true){alert(%22q
wertytis

This is due a lack of string stripping when putting the path into javascript.

It seems to w...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus