Lucene search

K
cveMicrosoftCVE-2014-1813
HistoryMay 14, 2014 - 11:13 a.m.

CVE-2014-1813

2014-05-1411:13:06
CWE-94
microsoft
web.nvd.nist.gov
46
cve-2014-1813
microsoft
web applications
2010
sp1
sp2
remote authenticated users
arbitrary code
crafted page content
vulnerability

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.02

Percentile

89.0%

Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka “Web Applications Page Content Vulnerability.”

Affected configurations

Nvd
Node
microsoftweb_applicationsMatch2010sp1
OR
microsoftweb_applicationsMatch2010sp2
VendorProductVersionCPE
microsoftweb_applications2010cpe:2.3:a:microsoft:web_applications:2010:sp1:*:*:*:*:*:*
microsoftweb_applications2010cpe:2.3:a:microsoft:web_applications:2010:sp2:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.02

Percentile

89.0%