CVE-2008-4032
Published Dec 10, 2008
Last updated 6 years ago
Overview
- Description
- Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
- Source
- secure@microsoft.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:office_sharepoint_server:2007:*:x32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27885107-A157-4BF0-A72C-2DEF0B24A723" }, { "criteria": "cpe:2.3:a:microsoft:office_sharepoint_server:2007:*:x64:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9144DFDA-7A7A-452C-AE4C-1A45F56B0F37" }, { "criteria": "cpe:2.3:a:microsoft:office_sharepoint_server:2007:sp1:x32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E013CE59-0ABF-4542-A9E9-D295AA0FC2A2" }, { "criteria": "cpe:2.3:a:microsoft:office_sharepoint_server:2007:sp1:x64:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C0AEECDD-BBD0-4042-8A47-D66670A6DC6E" }, { "criteria": "cpe:2.3:a:microsoft:search_server:2008:*:x32:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BAED31C-1137-463E-A814-FFBFF3648ADF" }, { "criteria": "cpe:2.3:a:microsoft:search_server:2008:*:x64:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DAD6B519-DD1E-4230-AF7C-0D6DE6EF4FF8" } ], "operator": "OR" } ] } ]