[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft SharePoint Spoofing Vulnerability - CVE-2019-0670

ID: oval:org.secpod.oval:def:50696Date: (C)2019-02-13   (M)2021-09-11
Class: VULNERABILITYFamily: windows




A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content or serve as a pivot the chain an attach with other vulnerabilities in web services. To exploit the vulnerability, the user must click a specially crafted URL. In an application-based attack scenario, an attacker could manipulate specific parameters and create a specially crafted URL in attempt to convince the user to click it. In a web-based attack scenario, an attacker could host a specially crafted website designed to appear as a legitimate website to the user. However, the attacker would have no way to force the user to visit the specially crafted website. The attacker would have to convince the user to visit the specially crafted website, typically by way of enticement in an email or instant message, and then convince the user to interact with content on the website. The security update addresses the vulnerability by correcting how Microsoft SharePoint handles URL redirects.

Platform:
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows 10
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows XP
Product:
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Reference:
CVE-2019-0670
CVE    1
CVE-2019-0670
CPE    4
cpe:/a:microsoft:sharepoint_foundation:2013
cpe:/a:microsoft:sharepoint_foundation:2013:sp1
cpe:/a:microsoft:sharepoint_server:2013:sp1
cpe:/a:microsoft:sharepoint_server:2013
...

© SecPod Technologies