[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Team Foundation Server Cross-site Scripting Vulnerability - CVE-2019-0647

ID: oval:org.secpod.oval:def:50206Date: (C)2019-01-16   (M)2021-06-02
Class: VULNERABILITYFamily: windows




The host is installed with Team Foundation 2018 Server Update 1.1 or Update 3 and is prone to a cross-site scripting vulnerability. The application fails to properly sanitize user provided input. On successful exploitation, an attacker could send a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised page.

Platform:
Microsoft Windows 10
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Product:
Microsoft Visual Studio Team Foundation Server 2018 Update 1.2
Microsoft Visual Studio Team Foundation Server 2018 Update 3.2
Microsoft Visual Studio Team Foundation Server 2017 Update 3.1
Reference:
CVE-2019-0647
CVE    1
CVE-2019-0647
CPE    5
cpe:/a:microsoft:visual_studio_team_foundation_server:2017:u3.1
cpe:/a:microsoft:visual_studio_team_foundation_server:2017
cpe:/a:microsoft:visual_studio_team_foundation_server:2018
cpe:/a:microsoft:visual_studio_team_foundation_server:2018:u3.2
...

© SecPod Technologies