CVE-2008-5026
Microsoft Sharepoint Server - XSS
Title source: ruleDescription
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.
References (5)
Scores
EPSS
0.1482
EPSS Percentile
94.4%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
microsoft/sharepoint_server
n/a/n/a
Timeline
Published
Nov 10, 2008
Tracked Since
Feb 18, 2026