SharePoint Permissions Privileges and Access Controls Vulnerability - CVE-2013-3895
Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page aka quotParameter Injection Vulnerability.quot