PT-2002-2268 · Microsoft · Office Web Components

Publicado

2002-12-11

·

Atualizado

2016-10-18

·

CVE-2002-1339

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Office Web Components (OWC) 10
Description: The issue concerns the "XMLURL" property in the Spreadsheet component, which follows redirections. This allows remote attackers to determine if local files exist based on exceptions or to read WorkSheet XML files.
Recommendations: For Office Web Components (OWC) 10, consider restricting access to the Spreadsheet component until a fix is available. As a temporary workaround, avoid using the "XMLURL" property in sensitive operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1339

Produtos afetados

Office Web Components