iTnews
  • Home
  • News
  • Technology
  • Security

Microsoft warns of cross-site scripting error

By Shaun Nichols on May 3, 2010 12:03PM
Microsoft warns of cross-site scripting error

Sharepoint issue leaves users at risk for attack.

Microsoft is warning users following the discovery of a flaw which could leave its SharePoint platform at risk.

The company said that the SharePoint Server 2007 and SharePoint Services 3.0 components were vulnerable to a cross site scripting attack. Microsoft said that there have not yet been any reports of attacks targeting the vulnerability.

If targeted, Microsoft warns that the vulnerability could allow an attacker to access the SharePoint site with elevated privileges.

Administrators are being advised to apply an access control list to the SharePoint Help.aspx file to prevent unauthorised users from having access to the vulnerable components. Applying the measure will, however, disable the help function for all users on the affected SharePoint site.

The company noted that the cross-site scripting protections in Internet Explorer 8 could also help to prevent an attack.

Microsoft said that it is developing and fix and is currently planning to release the patch next month with its May security update.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
accessattackcompanymicrosoftscriptingsecuritysharepoint

Partner Content

The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats
Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance
Why Genworth Australia embraced low-code software development
Promoted Content Why Genworth Australia embraced low-code software development

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Shaun Nichols
May 3 2010
12:03PM
0 Comments

Related Articles

  • Don't remove PowerShell: US, UK and NZ security agencies
  • Microsoft warns Azure customers of flaw that could have permitted hackers access to data
  • Austrian spy firm accused by Microsoft says hacking tool was for EU states
  • Microsoft says Austrian firm behind spyware targeting law firms, banks
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Aussie Broadband nears end of NBN PoI fibre rollout

Aussie Broadband nears end of NBN PoI fibre rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Student details, photos exposed in University of WA data breach

Student details, photos exposed in University of WA data breach

Defence, DEWR drop $160m on Microsoft software, Azure

Defence, DEWR drop $160m on Microsoft software, Azure

Digital Nation

Case Study: Multicloud business drivers at MLC Life Insurance
Case Study: Multicloud business drivers at MLC Life Insurance
Case Study: Swinburne University overhauls student management system
Case Study: Swinburne University overhauls student management system
COVER STORY: What happens when Google changes its algorithm?
COVER STORY: What happens when Google changes its algorithm?
Personalisation strategies need to be built from the ground up
Personalisation strategies need to be built from the ground up
COVER STORY: Multiple cloud models make security more complex
COVER STORY: Multiple cloud models make security more complex
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.