CVE-2005-0049

SharePoint Portal Server - Cross-Site Scripting via HTTP Redirection Query

Title source: llm
STIX 2.1

Description

Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19091
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/340409
Patch, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-039A.html

Scores

EPSS 0.2019
EPSS Percentile 97.2%

Details

Status published
Products (2)
microsoft/sharepoint_portal_server 2003 (2 CPE variants)
microsoft/sharepoint_team_services
Published May 02, 2005
Tracked Since Feb 18, 2026