2007-12-28 Windows SharePoint Services 3.0與Office SharePoint Server 2007允許權限於SharePoint網站環境內提升弱點
漏洞編號:
Bugtraq ID:
23832
漏洞編號:
CVE-2007-2581
影響平台:
Microsoft Windows SharePoint Services 3.0
+ 3DM Software Disk Management Software SP2
+ 3DM Software Disk Management Software SP1 Platform SDK
+ 3DM Software Disk Management Software SP1
+ Microsoft Windows Server 2003 Datacenter Edition SP1
+ Microsoft Windows Server 2003 Datacenter Edition
+ Microsoft Windows Server 2003 Datacenter x64 Edition SP2
+ Microsoft Windows Server 2003 Datacenter x64 Edition
+ Microsoft Windows Server 2003 Enterprise Edition SP1
+ Microsoft Windows Server 2003 Enterprise Edition
+ Microsoft Windows Server 2003 Enterprise x64 Edition SP2
+ Microsoft Windows Server 2003 Enterprise x64 Edition
+ Microsoft Windows Server 2003 Standard Edition SP2
+ Microsoft Windows Server 2003 Standard Edition SP1
+ Microsoft Windows Server 2003 Standard Edition
+ Microsoft Windows Server 2003 Standard x64 Edition
+ Microsoft Windows Server 2003 Web Edition SP2
+ Microsoft Windows Server 2003 Web Edition SP1
+ Microsoft Windows Server 2003 Web Edition
+ Microsoft Windows Server 2003 x64 SP2
+ Microsoft Windows Server 2003 x64 SP1
Microsoft SharePoint Server 2007 0
Microsoft Microsoft Office SharePoint Server 2007 x64 0
Microsoft Microsoft Office SharePoint Server 2007 0
漏洞概述:
Microsoft Windows SharePoint Services 3.0以及Microsoft Office SharePoint Server 2007存有允許權限於SharePoint網站環境內提升之弱點,可能會允許攻擊者執行任意指令碼而導致SharePoint網站內的權限提高 (並非提高在該工作站或伺服器環境中的權限)。此弱點也可能會允許攻擊者執行任意指令碼來修改使用者的快取,可能會導致工作站端資訊洩漏。
漏洞說明:
Microsoft Windows SharePoint Services 3.0以及Microsoft Office SharePoint Server 2007存有允許權限於SharePoint網站環境內提升之弱點,可能會允許攻擊者執行任意指令碼而導致SharePoint網站內的權限提高 (並非提高在該工作站或伺服器環境中的權限)。此弱點也可能會允許攻擊者執行任意指令碼來修改使用者的快取,可能會導致工作站端資訊洩漏。
影響狀況:
權限提升,執行程式碼。
解決方案:
請更新修補程式,可參考下列連結:
https://www.microsoft.com/technet/security/Bulletin/MS07-059.mspx
參考資料:
https://www.securityfocus.com/bid/23832
https://www.securityfocus.com/archive/1/467738 |