CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
99.8%
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka โMalformed Request Code Execution Vulnerability.โ
Vendor | Product | Version | CPE |
---|---|---|---|
microsoft | sharepoint_server | 2007 | cpe:2.3:a:microsoft:sharepoint_server:2007:sp2:x32:*:*:*:*:* |
microsoft | sharepoint_server | 2007 | cpe:2.3:a:microsoft:sharepoint_server:2007:sp2:x64:*:*:*:*:* |
osvdb.org/69817
secunia.com/advisories/42631
www.securityfocus.com/bid/45264
www.securitytracker.com/id?1024886
www.us-cert.gov/cas/techalerts/TA10-348A.html
www.vupen.com/english/advisories/2010/3226
www.zerodayinitiative.com/advisories/ZDI-10-287/
docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737