Lucene search

K
cveMicrosoftCVE-2013-0084
HistoryMar 13, 2013 - 12:55 a.m.

CVE-2013-0084

2013-03-1300:55:01
CWE-22
microsoft
web.nvd.nist.gov
122
cve-2013-0084
microsoft sharepoint
directory traversal
vulnerability
security
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.822

Percentile

98.4%

Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka “SharePoint Directory Traversal Vulnerability.”

Affected configurations

Nvd
Node
microsoftsharepoint_foundationMatch2010sp1
OR
microsoftsharepoint_serverMatch2010sp1
VendorProductVersionCPE
microsoftsharepoint_foundation2010cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp1:*:*:*:*:*:*
microsoftsharepoint_server2010cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.822

Percentile

98.4%