CVE-2010-0817
EXPLOITEDMicrosoft SharePoint Server 2007 <12.0.0.6421 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappswindows
https://www.exploit-db.com/exploits/12450
References (5)
Scores
EPSS
0.5532
EPSS Percentile
98.0%
Exploitation Intel
VulnCheck KEV
2010-06-08
Classification
CWE
CWE-79
Status
published
Affected Products (6)
microsoft/sharepoint_server
microsoft/sharepoint_services
microsoft/sharepoint_services
microsoft/sharepoint_services
microsoft/sharepoint_services
n/a/n/a
Timeline
Published
Apr 29, 2010
Tracked Since
Feb 18, 2026