Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness

Microsoft reported that this issue is being exploited in limited attacks in the wild.

Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.

The following example URI is available:

hcp://system/sysinfo/sysinfomain.htm?svr=<h1>test</h1>


 

Privacy Statement
Copyright 2010, SecurityFocus