Microsoft Internet Explorer 5.01 and...

- AV AC AU C I A
发布: 2000-06-27
修订: 2025-04-13

It is possible to remotely execute Visual Basic for Applications (VBA) code on systems running Internet Explorer 5.01 and Access 2000 or 97 through web pages or HTML email messages utilizing IFRAME without the user's consent or acknowledgement. *.mdb files can be created which contain VBA code, including the shell() command which can be used to run any executable file already on the system. These mdb files can then be referenced from an object tag in any html file loaded by the browser. The code will still execute even if the option of "Run ActiveX controls and plug-ins" is set to disable or prompt.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息