← Vulnerability feed

Vulnerability record · CVE-2005-0049 · published 2 May 2005

CVE-2005-0049: Microsoft sharepoint portal server vulnerability

Microsoft · Sharepoint Portal Server

Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.

4.3 CVSS 2.0 Medium EPSS 20% · top 2.6%
4.3CVSS 2.0 base score
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0049 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-1330Microsoft sharepoint foundation improper input validation vulnerabilityThe default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 d…EPSS 27%9.3CVE-2013-1315Microsoft excel memory buffer overflow vulnerabilityMicrosoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT…EPSS 29%9.3CVE-2013-3847Microsoft sharepoint foundation memory buffer overflow vulnerabilityMicrosoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2…EPSS 21%7.5CVE-2003-0822Microsoft FrontPage Server Extensions debug buffer overflowA buffer overflow exists in the debug functionality of fp30reg.dll in Microsoft FrontPage Server Extensions 2000 and 2002. A remote attacker can trig…EPSS 81%analysed6.8CVE-2006-0015Microsoft frontpage server extensions vulnerabilityCross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services…EPSS 24%6.8CVE-2004-0379Microsoft sharepoint portal server vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web conten…EPSS 8.1%5.0CVE-2013-0081Microsoft SharePoint unassigned workflow handling denial of serviceSharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1/SP2, and 2013 fail to properly process unassigned workflows. A crafted URL…EPSS 77%analysed5.0CVE-2003-0824Microsoft frontpage server extensions vulnerabilityUnknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team …EPSS 35%

Source: NIST National Vulnerability Database (record CVE-2005-0049), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.