CVE-2015-1633 (CNNVD-201503-275)
中文标题:
Microsoft SharePoint 跨站脚本漏洞
英文标题:
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Ser...
漏洞描述
中文描述:
Microsoft SharePoint Foundation和SharePoint Server都是美国微软(Microsoft)公司的业务协作平台。该平台用于对业务信息进行整合,并能够共享工作、与他人协同工作等。 Microsoft SharePoint中存在跨站脚本漏洞,该漏洞源于程序未正确地清理发往受影响的SharePoint server的经特殊设计的请求。经过身份验证的攻击者可通过向受影响的SharePoint服务器发送经特殊设计的请求利用该漏洞在受影响的系统上执行跨站点脚本攻击,并在当前用户的安全上下文中运行脚本,也可能读取未授权阅读的内容或者SharePoint网站上执行未授权的操作。以下版本受到影响:Microsoft SharePoint Foundation 2010 SP2,SharePoint Server 2010 SP2,SharePoint Foundation 2013 Gold和SP1,SharePoint Server 2013 Gold 和SP1。
英文描述:
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| microsoft | sharepoint_foundation | 2010 | - | - |
cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:*
|
| microsoft | sharepoint_foundation | 2013 | - | - |
cpe:2.3:a:microsoft:sharepoint_foundation:2013:-:-:*:gold:*:*:*
|
| microsoft | sharepoint_server | 2010 | - | - |
cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*
|
| microsoft | sharepoint_server | 2013 | - | - |
cpe:2.3:a:microsoft:sharepoint_server:2013:-:-:*:gold:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:M/Au:S/C:N/I:P/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2015-1633 |
2025-11-11 15:18:54 | 2025-11-11 07:34:00 |
| NVD | nvd_CVE-2015-1633 |
2025-11-11 14:54:49 | 2025-11-11 07:42:42 |
| CNNVD | cnnvd_CNNVD-201503-275 |
2025-11-11 15:09:33 | 2025-11-11 07:51:52 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 跨站脚本
- cnnvd_id: 未提取 -> CNNVD-201503-275
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.LOW
- cvss_score: 未提取 -> 3.5
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:S/C:N/I:P/A:N
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']