Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The InfoPath Forms Services component in Microsoft SharePoint Server 2007 SP3 and 2010 SP2 misparses DTDs, which allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "Microsoft SharePoint Information Disclosure Vulnerability."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft SharePoint Server 信息泄漏漏洞
Vulnerability Description
Microsoft SharePoint Server是美国微软(Microsoft)公司的一套企业业务协作平台。该平台用于对业务信息进行整合,并能够共享工作、与他人协同工作、组织项目和工作组、搜索人员和信息。 Microsoft SharePoint Server 2007 SP3版本和2010 SP2版本的InfoPath Forms Services组件中存在信息泄漏漏洞,该漏洞源于程序不正确地分析XML文件的文档类型定义(DTD)。远程攻击者可利用该漏洞浏览SharePoint服务器上的任意文件的
CVSS Information
N/A
Vulnerability Type
N/A