CVE-2009-3830
published 2009-10-30CVE-2009-3830: The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET…
PriorityP342medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
32.61%
98.1th percentile
The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sharepoint_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttp://server/_layouts/download.aspx?SourceUrl=/Pages/Default.aspx&Source=http://server/Pages/Default.aspx&FldUrl=↗
- →Monitor HTTP requests to /_layouts/download.aspx containing both SourceUrl and Source parameters pointing to .aspx files, which indicates attempted ASP.NET source code disclosure. ↗
- →Alert on requests to /_layouts/download.aspx where SourceUrl parameter contains paths NOT starting with /_layouts/, as these target backend-database-stored files for source disclosure. ↗
- →Affected versions are SharePoint 2007 12.0.0.6219 and 12.0.0.4518; scope detection rules to these version strings. ↗
- ·No patch was available at time of disclosure; Microsoft addressed design issues in KB976829 rather than issuing a direct fix, so patching status must be verified against the KB article. ↗
- ·The vulnerability affects files stored in the backend database; files whose path starts with /_layouts/ are not retrievable via this method, limiting the attack surface to user-uploaded and custom ASP.NET pages. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://support.microsoft.com/kb/976829http://www.securityfocus.com/archive/1/507419/100/0/threadedhttp://www.securityfocus.com/bid/36817https://exchange.xforce.ibmcloud.com/vulnerabilities/53955http://support.microsoft.com/kb/976829http://www.securityfocus.com/archive/1/507419/100/0/threadedhttp://www.securityfocus.com/bid/36817https://exchange.xforce.ibmcloud.com/vulnerabilities/53955
2009-10-30
Published