CVE Vulnerabilities

CVE-2006-7037

Published: Feb 23, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the is-locked attribute, and (4) view locked data, which is stored in plaintext.

Affected Software

Name Vendor Start Version End Version
Windows_2000 Microsoft * *
Windows_2003_server Microsoft sp2 (including) sp2 (including)
Windows_95 Microsoft * *
Windows_98 Microsoft * *
Windows_98se Microsoft * *
Windows_me Microsoft * *
Windows_nt Microsoft 4.0 (including) 4.0 (including)
Windows_xp Microsoft * *

References