CVE-2012-1858
The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
- Affected products
- Ge Communicator, Internet Explorer, Lync, Sharepoint Foundation, Sharepoint Server
- Microsoft Lync
- = 2010
- Microsoft Office Communicator
- = 2007
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 22.0% (97th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2012-06-12
CVE-2012-1858 at NVD
6 known exploits for CVE-2012-1858
Proof-of-concept code and exploit modules indexed by Sploitus
IE9, SharePoint, Lync toStaticHTML HTML Sanitizing Bypass
Microsoft Internet Explorer 9 SharePoint Lync - toStaticHTML HTML Sanitizing Bypass (MS12-037MS12-039MS12-050)
Microsoft Internet Explorer 9 / SharePoint / Lync - toStaticHTML HTML Sanitizing Bypass (MS12-037/MS12-039/MS12-050)
IE9 / SharePoint / Lync toStaticHTML HTML Sanitizing Bypass
toStaticHTML HTML Sanitizing Bypass
Microsoft Lync/Office Communicator HTML代码过滤漏洞 (CVE-2012-1858) (MS12-039)