PT-2005-1849 · Microsoft · Office Infopath 2003 Sp1
Published
2005-03-20
·
Updated
2008-09-05
·
CVE-2005-0820
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Office InfoPath 2003 SP1
Description
The issue allows attackers to obtain sensitive information, including printer and network details, database name, username, password, or the internal web server name, due to the inclusion of this information in the Manifest.xsf file in a custom .xsn form.
Recommendations
For Microsoft Office InfoPath 2003 SP1, consider removing or securing sensitive information from the Manifest.xsf file in custom .xsn forms to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Infopath 2003 Sp1