CVE-2002-0727

3 documents3 sources
Severity
7.5HIGH
EPSS
9.5%
top 7.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateApr 30

Description

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gx66-9wfp-gpfc: The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows2022-04-30
CVEList
CVE-2002-0727: The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows2003-04-02
CVE-2002-0727 (HIGH CVSS 7.5) | The Host function in Microsoft Offi | cvebase.io