ID |
CVE-2008-3003
|
Sažetak |
Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability." |
Reference |
|
CVSS |
Base: | 6.6 |
Impact: | 9.2 |
Exploitability: | 3.9 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
LOW |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
COMPLETE |
COMPLETE |
NONE |
|
CVSS vektor |
AV:L/AC:L/Au:N/C:C/I:C/A:N |
Zadnje važnije ažuriranje |
12-10-2018 - 21:47 |
Objavljeno |
12-08-2008 - 23:41 |