guninski-53.txt...

- AV AC AU C I A
发布: 2002-04-02
修订: 2025-04-13

Georgi Guninski security advisory #53, 2002 - Two serious security vulnerabilities have been found in Microsoft Office XP. It is possible to embed active content (object + script) in HTML mail which is triggered if the user replies to or forwards mail. In addition, a bug in the Host() function of the spreadsheet allows creating files with arbitrary names and their content may be specified to some extent at which is sufficient to place an executable file (.hta) in user's startup directory which may lead to taking full control over user's computer.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息