Show plain JSON{"id": "CVE-2012-1860", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:P", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2012-07-10T21:55:05.790", "references": [{"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-050", "source": "secure@microsoft.com"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15265", "source": "secure@microsoft.com"}, {"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-050", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15265", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-264"}]}], "descriptions": [{"lang": "en", "value": "Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka \"SharePoint Search Scope Vulnerability.\""}, {"lang": "es", "value": "Microsoft Office SharePoint Server 2007 SP2 y SP3, SharePoint Server 2010 Gold y SP1, y Office Web Apps 2010 Gold y SP1 no comprueba correctamente los permisos para los \u00e1mbitos de b\u00fasqueda, permitiendo a usuarios remotos autenticados obtener informaci\u00f3n sensible o causar una denegaci\u00f3n de servicio (modificaci\u00f3n de datos) al cambiar un par\u00e1metro en una URL de b\u00fasqueda, tambi\u00e9n conocido como \"SharePoint Search Scope Vulnerability.\""}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:office_web_apps:2010:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FEAB1E34-AAEE-4C01-8FA8-6099A74F0731"}, {"criteria": "cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "343EEB54-C1B1-4D7B-8780-5B5A5F2F840C"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2007:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF3C2971-447B-4054-86C6-3169B82E525B"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2007:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C24FB09-DBAD-4F62-BBD6-B81B9EC83D56"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2007:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B7AEA5E-C3D7-4E6D-96F0-5F9A175631C9"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2010:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCBCB0A0-BC40-4E6B-BD06-A137BB964B7F"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FA65D4A-00C8-47E2-AF9F-6B420017CD29"}], "operator": "OR"}]}], "sourceIdentifier": "secure@microsoft.com"}