CVE-2011-1892

Scores

EPSS

0.621medium62.1%
0%20%40%60%80%100%

Percentile: 62.1%

CVSS

4.0medium2.0
0246810

CVSS Score: 4.0/10

All CVSS Scores

CVSS 2.0
4.0

Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Description

Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka “SharePoint Remote File Disclosure Vulnerability.”

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-200

Exploits

Exploit ID: 17873

Source: exploitdb

URL: https://www.exploit-db.com/exploits/17873

Vulnerable Software (10)

Type: Configuration

Vendor: *

Product: forms_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: groove

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: groove_data_bridge_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: groove_management_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: groove_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: office_web_apps

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: sharepoint_foundation

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: sharepoint_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: sharepoint_services

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

Type: Configuration

Vendor: *

Product: sharepoint_workspace

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2:x32:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:forms_server:2007:sp2...

Source: nvd

End of list