CVE Database
/

CVE-2011-1252

Back to search

CVE-2011-1252

Published: Jun 16, 2011

Modified: Jan 21, 2025

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

MS11-074
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:12885
vdb-entry
signature
x_refsource_OVAL
MS11-050
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:12577
vdb-entry
signature
x_refsource_OVAL
TA11-256A
third-party-advisory
x_refsource_CERT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now