CVE-2002-0860

3 documents3 sources
Severity
5.0MEDIUM
EPSS
31.7%
top 3.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateApr 30

Description

The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmicrosoft/project2000, 2002+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-27pr-43qm-8hmf: The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary file2022-04-30
CVEList
CVE-2002-0860: The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary file2003-04-02
CVE-2002-0860 (MEDIUM CVSS 5) | The LoadText method in the spreadsh | cvebase.io