CVE-2016-7251
published 2016-11-10CVE-2016-7251: Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an…
PriorityP431medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
8.19%
94.2th percentile
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sql_server | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc6.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
MDS API XSS Vulnerability
vendor_msrc·2016-11-08·CVSS 6.1
CVE-2016-7251 [MEDIUM] MDS API XSS Vulnerability
MDS API XSS Vulnerability
Description: A cross-site scripting vulnerability exists in SQL Server MDS that could allow an attacker to inject a client-side script into the user's browser instance. The vulnerability is caused when the SQL Server MDS does not properly validate a request parameter on the SQL Server site. The script could spoof content, disclose information, or take any action that the user could take on the site on behalf of the targeted user.
To exploit the vulnerability, the user must click a specially crafted URL. In an email attack scenario, an attacker could send an email message containing the specially crafted URL to the user in an attempt to convince the user to click it.
The security update addresses the vulnerability by correcting how SQL Server MDS validates the req
GHSA
GHSA-664m-vm73-69h5: Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML vi
ghsa_unreviewed·2022-05-14
CVE-2016-7251 [MEDIUM] CWE-79 GHSA-664m-vm73-69h5: Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML vi
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94043http://www.securitytracker.com/id/1037250https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-136http://www.securityfocus.com/bid/94043http://www.securitytracker.com/id/1037250https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-136
2016-11-10
Published