Record summary

CVE-2010-3324 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft Internet Explorer 8 - 'toStaticHTML()' HTML Sanitization BypassExploitDB exploitby Mario HeiderichNot analyzed1 file
ExploitDB

PoC details

References

8