CVE-2010-3324
The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
- Affected products
- Groove Server 2010, Internet Explorer, Internet Explorer 8, Windows Sharepoint Services 3.0 Sp2, Office Sharepoint Server 2007 Sp2, Office Web Apps, Sharepoint Foundation 2010, Sharepoint Foundation
- Microsoft Groove Server
- = 2010
- Microsoft Internet Explorer
- = 8
- Microsoft Sharepoint Foundation
- = 2010
- Microsoft Sharepoint Server
- = 2007
- Microsoft Sharepoint Services
- = 3.0
- Microsoft Web Apps
- All versions
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 17.2% (97th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2010-09-17
CVE-2010-3324 at NVD
2 known exploits for CVE-2010-3324
Proof-of-concept code and exploit modules indexed by Sploitus