← All CVEs

CVE-2013-0081

medium · 5

Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."

5
CVSS
76.7%
EPSS (exploit prob.)
100th
EPSS percentile
2013-09-11
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftsharepoint_foundation2010
microsoftsharepoint_foundation2010
microsoftsharepoint_foundation2013
microsoftsharepoint_portal_server2003
microsoftsharepoint_server2007
microsoftsharepoint_server2010
microsoftsharepoint_server2010
microsoftsharepoint_server2013
microsoftsharepoint_services2.0
microsoftsharepoint_services3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-0081