The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=101830175621193&w=2 | |
http://security.greymagic.com/adv/gm008-ie/ | Exploit Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=101830175621193&w=2 | |
http://security.greymagic.com/adv/gm008-ie/ | Exploit Patch Vendor Advisory |
Configurations
History
20 Nov 2024, 23:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=101830175621193&w=2 - | |
References | () http://security.greymagic.com/adv/gm008-ie/ - Exploit, Patch, Vendor Advisory |
Information
Published : 2002-12-18 05:00
Updated : 2024-11-20 23:41
NVD link : CVE-2002-1339
Mitre link : CVE-2002-1339
CVE.ORG link : CVE-2002-1339
JSON object : View
Products Affected
microsoft
- office_web_components
CWE