CVE-2008-3003 - CERT CVE
ID CVE-2008-3003
Sažetak Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
Reference
CVSS
Base: 6.6
Impact: 9.2
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE NONE
CVSS vektor AV:L/AC:L/Au:N/C:C/I:C/A:N
Zadnje važnije ažuriranje 12-10-2018 - 21:47
Objavljeno 12-08-2008 - 23:41