PT-2002-2269 · Microsoft · Office Web Components
Published
2002-12-11
·
Updated
2016-10-18
·
CVE-2002-1340
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Office Web Components (OWC) version 10
Description:
The issue allows remote attackers to determine the existence of local files by detecting an exception related to the "ConnectionFile" property in the DataSourceControl component.
Recommendations:
For Office Web Components (OWC) version 10, consider restricting access to the DataSourceControl component to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Web Components