Microsoft InfoPath and Groove Server Cross-Site Scripting Vulnerability
Description
A vulnerability has been reported in Microsoft InfoPath and Microsoft Groove Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
Certain input is not properly sanitised in the "SafeHTML" API before being returned to the user.
For more information see vulnerability #2:
SA49412
Vulnerable Products
Vulnerable Software: Microsoft Groove Server 2010Microsoft InfoPath 2010Microsoft Office InfoPath 2007