All the latest UK technology news, reviews and analysis

Microsoft warns of cross-site scripting error

by Shaun Nichols

01 May 2010

Be the first to comment

  • Tweet this
Microsoft bug
Microsoft is warning of a flaw in SharePoint

Microsoft is warning of a flaw in SharePoint Server 2007 and SharePoint Services 3.0 which could allow a cross-site scripting attack.

The company said that there have been no reports of attacks targeting the vulnerability, which could allow an attacker to access the SharePoint site with elevated privileges.

Administrators are advised to apply an access control list to the SharePoint Help.aspx file to prevent unauthorised users gaining access to the vulnerable components.

Applying the measure will, however, disable the help function for all users on the affected SharePoint site.

Microsoft noted that the cross-site scripting protections in Internet Explorer 8 could also help to prevent an attack.

The firm is developing and fix and is currently planning to release a patch next month with its May security update.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

32%

2%

15%

51%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Sales Consultant - Datacentre

Sales Consultant - Data Centre, Colocation, Hosting...

Senior Interaction Designer (User Experience, UCD, Prototypes)

Senior Interaction Designer (User Experience, UCD, Interactive...

Head of Information Architecture / UX - London - £370p/d

Information Architecture / IA / User Experience / UX...

Sales Consultant

Sales Consultant A rapidly expanding independent managed...

To send to more than one email address, simply separate each address with a comma.