CVE Vulnerabilities

CVE-2002-0727

Published: Sep 24, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

Affected Software

NameVendorStart VersionEnd Version
Office_web_componentsMicrosoft2000 (including)2000 (including)
Office_web_componentsMicrosoft2002 (including)2002 (including)
ProjectMicrosoft2002 (including)2002 (including)

References