Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3007

Опубликовано: 11 сент. 2008
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2007:*:gold:*:*:*:*:*
cpe:2.3:a:microsoft:office:2007:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_onenote:2007:gold:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_onenote:2007:sp1:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.5913
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."

EPSS

Процентиль: 98%
0.5913
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20