[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft SharePoint Information Disclosure Vulnerability - CVE-2018-8580

ID: oval:org.secpod.oval:def:49707Date: (C)2018-12-12   (M)2022-10-10
Class: VULNERABILITYFamily: windows




An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user. While the attacker cant access the search results or documents as such, the attacker can determine whether the query did return results or not, and thus by issuing targeted queries discover facts about documents that are searchable for the logged-in user. The security update addresses the vulnerability by running the search queries in a way that doesnt expose them to this browser vulnerability.

Platform:
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows 10
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows XP
Product:
Microsoft SharePoint Foundation 2010
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
Reference:
CVE-2018-8580
CVE    1
CVE-2018-8580
CPE    5
cpe:/a:microsoft:sharepoint_foundation:2010
cpe:/a:microsoft:sharepoint_foundation:2010:sp2
cpe:/a:microsoft:sharepoint_server:2016
cpe:/a:microsoft:sharepoint_server:2013:sp1
...

© SecPod Technologies