4.3
CVSSv2

CVE-2010-1257

Published: 08/06/2010 Updated: 07/12/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote malicious users to inject arbitrary web script or HTML via vectors related to sanitization.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office infopath 2003

microsoft office infopath 2007

microsoft sharepoint server 2007

microsoft sharepoint services 3.0

microsoft internet_explorer 8