Microsoft Office XP Spreadsheet...

- AV AC AU C I A
发布: 2002-03-31
修订: 2025-04-13

Microsoft Office XP provides a spreadsheet component that can be embedded in web pages and office documents. This spreadsheet component contains a bug in a function called HOST() that can be exploited to write arbitrary files. This can be done from office documents, and possibly other vectors such as HTML mail. This is accomplished by embedding a spreadsheet object containing a formula similar to the following: =Host().SaveAs("arbitraryfilename") Microsoft has released patches which address a related vulnerability (BugTraq ID 4397 "Microsoft Outlook HTML Mail Script Execution Vulnerability"). However, it has been reported that these patches do not address this issue in the Excel component of Office XP.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息