Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3003

Опубликовано: 12 авг. 2008
Источник: nvd
CVSS2: 6.6
EPSS Низкий

Описание

Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2007:*:gold:*:*:*:*:*
cpe:2.3:a:microsoft:office:2007:sp1:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00947
Низкий

6.6 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."

EPSS

Процентиль: 76%
0.00947
Низкий

6.6 Medium

CVSS2

Дефекты

CWE-20