Search/CVE-2007-2581
CVE

CVE-2007-2581

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.

CVSS v3.1
EPSS
36.2%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
4 relationships
Timeline
disclosure → media coverage
May 9, 2007
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026