Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76gc-c529-wjrc

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."

Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."

EPSS

Процентиль: 98%
0.5913
Средний

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 17 лет назад

Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."

EPSS

Процентиль: 98%
0.5913
Средний

Дефекты

CWE-20