Oval Definition:oval:org.mitre.oval:def:7637
Revision Date:2014-08-18Version:53
Title:HTML Sanitization Vulnerability (CVE-2010-3243)
Description:Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-3243
Platform(s):Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer 8
Microsoft Office SharePoint Server 2007
Microsoft Windows SharePoint Services 3.0
Definition Synopsis
  • Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64
  • Windows XP, Server 2003
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 8 is installed
  • AND GDR or QFE Service branch
  • Mshtml.dll version is less than 8.0.6001.18975
  • OR QFE
  • Mshtml.dll version is greater than 8.0.6001.22000
  • AND Mshtml.dll version is less than 8.0.6001.23067
  • OR Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64
  • Vista x86/x64, all Server 2008 x86/x64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Microsoft Internet Explorer 8 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 8.0.6001.18975
  • OR LDR
  • Mshtml.dll version is greater than 8.0.6001.22000
  • AND Mshtml.dll version is less than 8.0.6001.23067
  • OR Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64
  • Windows 7, Server 2008 R2
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • AND Microsoft Internet Explorer 8 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 8.0.7600.16671
  • OR LDR
  • Mshtml.dll version is greater than or equal 8.0.7600.20000
  • AND Mshtml.dll version is less than 8.0.7600.20795
  • Vulnerable Microsoft Office SharePoint Server 2007
  • Microsoft Office SharePoint Server 2007 is installed.
  • AND the version of Osafehtm.dll is less than 12.0.6545.5000
  • Vulnerable Microsoft Windows SharePoint Services 3.0
  • Windows Server 2003 32-bit or Windows Server 2003 64-bit
  • Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Windows SharePoint Services 3.0 are installed
  • AND the version of Onetutil.dll is less than 12.0.6545.5002
  • BACK