CVE-2007-2581
published 2007-05-09CVE-2007-2581: Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
36.23%
98.3th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →XSS payload injected via PATH_INFO (query string) appended to SharePoint pages such as default.aspx; monitor HTTP requests where the path component after .aspx contains URL-encoded script characters (e.g., %22, %7B, %7D, alert) ↗
- →Alert for requests to SharePoint endpoints where the URI path beyond the .aspx filename contains JavaScript syntax patterns such as `if(true){alert(` or closing brace/parenthesis sequences indicative of script injection ↗
- ·The vulnerability affects every main SharePoint page, not just default.aspx; any .aspx page in the SharePoint installation may be a viable injection point via PATH_INFO ↗
- ·Affected products are Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 AND Office SharePoint Server 2007; both product lines require patching/mitigation ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2007-05/0196.htmlhttp://osvdb.org/37630http://secunia.com/advisories/27148http://securityreason.com/securityalert/2682http://securitytracker.com/id?1018789http://www.securityfocus.com/archive/1/467738/100/0/threadedhttp://www.securityfocus.com/archive/1/467749/100/0/threadedhttp://www.securityfocus.com/archive/1/482366/100/0/threadedhttp://www.securityfocus.com/bid/23832http://www.us-cert.gov/cas/techalerts/TA07-282A.htmlhttp://www.vupen.com/english/advisories/2007/3439https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-059https://exchange.xforce.ibmcloud.com/vulnerabilities/34343https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2286http://archives.neohapsis.com/archives/bugtraq/2007-05/0196.htmlhttp://osvdb.org/37630http://secunia.com/advisories/27148http://securityreason.com/securityalert/2682http://securitytracker.com/id?1018789http://www.securityfocus.com/archive/1/467738/100/0/threadedhttp://www.securityfocus.com/archive/1/467749/100/0/threadedhttp://www.securityfocus.com/archive/1/482366/100/0/threadedhttp://www.securityfocus.com/bid/23832http://www.us-cert.gov/cas/techalerts/TA07-282A.htmlhttp://www.vupen.com/english/advisories/2007/3439https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-059https://exchange.xforce.ibmcloud.com/vulnerabilities/34343https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2286
2007-05-09
Published