CVE Vulnerabilities

CVE-2002-0727

Published: Sep 24, 2002 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

Affected Software

Name Vendor Start Version End Version
Office_web_components Microsoft 2000 (including) 2000 (including)
Office_web_components Microsoft 2002 (including) 2002 (including)
Project Microsoft 2002 (including) 2002 (including)

References