CVE Database
/

CVE-2010-3324

Back to search

CVE-2010-3324

Published: Sep 17, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.

VendorProductVersions

n/a

n/a

affected
n/a

References

MS10-071
vendor-advisory
x_refsource_MS
20100814 IE8 toStaticHtml Bypass
mailing-list
x_refsource_FULLDISC
oval:org.mitre.oval:def:7297
vdb-entry
signature
x_refsource_OVAL
MS10-072
vendor-advisory
x_refsource_MS
TA10-285A
third-party-advisory
x_refsource_CERT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now