Definition
New Search
HTML Sanitization Vulnerability - MS12-050
oval:org.mitre.oval:def:15530
The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9 Communicator 2007 R2 and Lync 2010 and 2010 Attendee does not properly handle event attributes and script which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document aka "HTML Sanitization Vulnerability."
Family:
windows
Status:
ACCEPTED
Platform(s):
- Microsoft Windows 7
- Microsoft Windows Server 2008
- Microsoft Windows Vista
- Microsoft Windows Server 2003
- Microsoft Windows Server 2008 R2
- Microsoft Windows XP
Class:
vulnerability
Reference(s):
- CVE-2012-1858
Product(s):
- Microsoft SharePoint Foundation 2010
- Microsoft Lync 2010
- Microsoft InfoPath 2007
- Microsoft Communicator 2007 R2
- Microsoft SharePoint Services 3.0
- Microsoft InfoPath 2010
- Microsoft SharePoint Server 2007
- Microsoft Lync 2010 Attendee
- Microsoft SharePoint Server 2010
- Microsoft Internet Explorer 9
- Microsoft Internet Explorer 8
- Microsoft Groove Server 2010