6.8

CVE-2013-3895

Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parameter Injection Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Web Apps Version 2010
Microsoft ≫ Sharepoint Server Version 2007 Update sp3
Microsoft ≫ Sharepoint Server Version 2010 Update sp1
Microsoft ≫ Sharepoint Server Version 2010 Update sp2
Microsoft ≫ Sharepoint Server Version 2013
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 29.64% 0.98
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.us-cert.gov/ncas/alerts/TA13-288A
US Government Resource
http://blogs.technet.com/b/srd/archive/2013/10/08/assessing-risk-for-the-october-2013-security-updates.aspx
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-084
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18991