CVE-2012-0144Cross-site Scripting in Microsoft Sharepoint Foundation

Severity
4.3MEDIUMNVD
EPSS
35.9%
top 2.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 4

Description

Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-rg98-gh38-3h9w: Cross-site scripting (XSS) vulnerability in themeweb2022-05-04
CVEList
CVE-2012-0144: Cross-site scripting (XSS) vulnerability in themeweb2012-02-14

💥Exploits & PoCs

2
Exploit-DB
Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)2017-07-11
Exploit-DB
Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)2017-05-17

🕵️Threat Intelligence

1
Zscaler
Zscaler Protects against Microsoft's Patch Cycle | Round 12

💬Community

1
Bugzilla
CVE-2012-0767 flash-plugin: universal cross-site scripting flaw (APSB12-03)2012-02-16
CVE-2012-0144 — Cross-site Scripting in Microsoft | cvebase