CVE-2013-3179
Microsoft SharePoint Server 2007 SP3, 2010 SP1/SP2, 2013 - Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-3179. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This is a detailed writeup describing a persistent XSS vulnerability in Microsoft SharePoint 2013 (Cloud) due to improper input validation in the exception handling module. The vulnerability allows remote attackers to inject malicious script code via the `ms-descriptionText` and `TA_ManageBDCPermissions_data` parameters.
Description
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
Exploits (1)
This is a detailed writeup describing a persistent XSS vulnerability in Microsoft SharePoint 2013 (Cloud) due to improper input validation in the exception handling module. The vulnerability allows remote attackers to inject malicious script code via the `ms-descriptionText` and `TA_ManageBDCPermissions_data` parameters.