| ID |
CVE-2008-3003
|
| Sažetak |
Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability." |
| Reference |
|
| CVSS |
| Base: | 6.6 |
| Impact: | 9.2 |
| Exploitability: | 3.9 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| LOCAL |
LOW |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
COMPLETE |
NONE |
|
| CVSS vektor |
AV:L/AC:L/Au:N/C:C/I:C/A:N |
| Zadnje važnije ažuriranje |
12-10-2018 - 21:47 |
| Objavljeno |
12-08-2008 - 23:41 |