Lucene search

K
cveMicrosoftCVE-2013-0080
HistoryMar 13, 2013 - 12:55 a.m.

CVE-2013-0080

2013-03-1300:55:01
CWE-264
microsoft
web.nvd.nist.gov
118
sharepoint
microsoft
cve-2013-0080
vulnerability
remote attack
content hijacking

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.953

Percentile

99.4%

Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka “Callback Function Vulnerability.”

Affected configurations

Nvd
Node
microsoftsharepoint_foundationMatch2010sp1
OR
microsoftsharepoint_serverMatch2010sp1
VendorProductVersionCPE
microsoftsharepoint_foundation2010cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp1:*:*:*:*:*:*
microsoftsharepoint_server2010cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.953

Percentile

99.4%