Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.810693
Kategorie:Windows : Microsoft Bulletins
Titel:Microsoft Office Web Apps XSS Elevation of Privileges Vulnerability (KB3178725)
Zusammenfassung:This host is missing an important security; update for Microsoft Office Web Apps according to Microsoft security update; KB3178725
Beschreibung:Summary:
This host is missing an important security
update for Microsoft Office Web Apps according to Microsoft security update
KB3178725

Vulnerability Insight:
The flaw exists when an Office Web Apps server
does not properly sanitize a specially crafted request.

Vulnerability Impact:
An authenticated attacker could exploit the
vulnerability by sending a specially crafted request to an affected Office Web
Apps server. The attacker who successfully exploited this vulnerability could then
perform cross-site scripting attacks on affected systems and run script in the
security context of the current user.

Affected Software/OS:
Microsoft Office Web Apps Server 2013 Service Pack 1 and prior.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
3.5

CVSS Vector:
AV:N/AC:M/Au:S/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-0195
BugTraq ID: 97417
http://www.securityfocus.com/bid/97417
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.